cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
16657
Views
5
Helpful
12
Replies

error message "EST Service not running" since upgrade to 2.4

John Vierra
Cisco Employee
Cisco Employee

Ever since I upgrade to 2.4 I'm getting this error message "EST Service not running". If I look in the CLI is says its not running. Any ideas?

3 Accepted Solutions

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Yes, it's the same issue as CSCvj11319.

In John's case, he re-generated the ISE internal CA certificate chain.

View solution in original post

To fix the EST service not running following an upgrade just follow these screenshots.  I suggest engaging TAC if you are have problems or need help though. Make sure you weren't using the existing prior to this, if unsure contact TAC. 

 

 

Click on Generate CSR highlighted

generate.JPG

 

Then Select "Root CA" and click replace ISE root CA certificate chain.

iseroot.JPG

View solution in original post

Open a tac case
More information about getting help under resources http://cs.co/ise-help

View solution in original post

12 Replies 12

hslai
Cisco Employee
Cisco Employee

I already responded and suggested to meet and check this out.

chhess
Cisco Employee
Cisco Employee

Hello, i am having this same issue.  I see this is marked as "Solved" but there is not any information on what fixed this issue.  Is this the same bug as CSCvj11319, we upgraded from 2.2. 

hslai
Cisco Employee
Cisco Employee

Yes, it's the same issue as CSCvj11319.

In John's case, he re-generated the ISE internal CA certificate chain.

chhess
Cisco Employee
Cisco Employee

Thank you for the information!

for others that may find this, I would do this after the entire deployment has been upgraded, not just the after the PAN completes.

hi   hslai

How do I create an ISE internal CA certificate chain?

To fix the EST service not running following an upgrade just follow these screenshots.  I suggest engaging TAC if you are have problems or need help though. Make sure you weren't using the existing prior to this, if unsure contact TAC. 

 

 

Click on Generate CSR highlighted

generate.JPG

 

Then Select "Root CA" and click replace ISE root CA certificate chain.

iseroot.JPG

We tried this workaround in from CSCvj11319 bug but no luck. We are not using internal CA.

Open a tac case
More information about getting help under resources http://cs.co/ise-help

Is there anyway to disable EST services only ?

Hi Dear Damien Miller

I have the same problem on one of my PSN and I did your solution but it didn't work for me, any help?

I would reccomend contacting TAC if the process did not work. I have run in to issues since this thread where a cert db file may need to be cleared out from root.