cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4524
Views
2
Helpful
4
Replies

Cisco ISE Queue Link Error

Netmart
Level 7
Level 7

Hello,

We did receive the following alert:

Queue Link Error: Message=From ISE-Node1 to ISE-Node2-ISE-1.mskcc.org; Cause={tls_alert;{unknown_ca;"tls Client:

In State Certify At Ssl_handshake.erl:1887 Generated Client Alert: Fatal - Unknown Ca\n"}

What has been checked so far:

1) Service: Running at both nodes

ISE Messaging Service                  running          20704

2) Port is open at both nodes: show ports

     tcp: 0.0.0.0:15672, 0.0.0.0:8671, 0.0.0.0:8672

3) Cert validity check

Jun 16 2022  - Jun 17 2027

Jun 24 2024 - Jun 25 2029

Version: 

Cisco Identity Services Engine

---------------------------------------------

Version      : 3.1.0.518

Build Date   : Mon Aug  9 16:28:55 2021

Install Date : Fri Jun 17 07:29:59 2022

Cisco Identity Services Engine Patch

---------------------------------------------

Version      : 3

Install Date : Fri Jun 17 08:13:40 2022

 

Any advice is much appreciated.

1 Accepted Solution

Accepted Solutions

The error you are getting is stating "Unknown CA" which requires regenerating ISE root and ISE messaging service certificates as per the link shared by @Mark Elsen. In addition to the above link please check this video at minute 5:41:

ISE Messaging Services and Queue Link Errors

View solution in original post

4 Replies 4

Mark Elsen
Hall of Fame
Hall of Fame

 

  - FYI : https://community.cisco.com/t5/security-knowledge-base/ise-queue-link-error/ta-p/4625179

  M.



-- ' Listen to the wind, it talks  
          Listen to the silence, it speaks
            Listen to your heart, it knows

The error you are getting is stating "Unknown CA" which requires regenerating ISE root and ISE messaging service certificates as per the link shared by @Mark Elsen. In addition to the above link please check this video at minute 5:41:

ISE Messaging Services and Queue Link Errors

Thank you Aref.

This video worked for me: regenerating ISE root and ISE messaging service certificates fixed the issue.