04-30-2024 07:53 PM - last edited on 04-30-2024 08:42 PM by shazubai
Dear Community,
ISE 3.1 integrate with AD.
ISE certificate is nearly expire so we are testing to perform ISE ssl certificate.
1. We do CSR on ISE
2. Send CSR cert to system team to CA "certificate template and client computer certificate"
3. system team share us the new certificate
We done import on Trust Certificate.
But it is error when import this new cert to "System Certificate" -> message error "Private key File is required".
Please kindly advise and next action to resolve it.
Thanks,
04-30-2024 11:19 PM
check the below document - you can verify the cert on your PC using notepad or MMC console.
check some troubleshooting tips - verify the cert - if you have openssl on command line tool
04-30-2024 11:22 PM
@Da ICS16 sounds like you are going to the wrong place, you need to bind the signed certificate.
Navigate Administration > System >Certificates > Certificate Signing Requests, then tick the checkbox on CSR and click Bind Certificate: then select the signed identity certificate.
Refer to the Install certificate section - https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html#toc-hId-18233342
05-01-2024 11:17 PM
Dear @Rob Ingram ,
After Bind Certificate so no need to import new certificate to "System Certificates"?
It mean no need to import any cert to System Certificates?
Thanks,
05-02-2024 12:03 AM
@Da ICS16 no, when you bind the certificate you just select the usage, Admin, EAP, Portal etc. The certificate is then configured for use.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide