05-31-2023 04:22 AM
Hi there,
We have a bunch of system Certificates expiring ASAP in a PAN failover depoyment (Primary & Secondary)
Can you aid in the correct steps to carry out this work. Can you actually import the new certs whilst the others are active and then just delete them when new certs are active?
I look forward to hearing back
Solved! Go to Solution.
05-31-2023 04:30 AM
@patrickbyrne456305724 replacing the "admin" certificate will result in restarting the ISE services. Replacing the other certificates does not result in restarting the services. Obviously for the EAP certificate you need to ensure the clients trust the ISE certificate, so use the same CA to issue the certificate and you should be fine.
Here is a cisco guide to renew ISE certificates - https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html
Once you've replaced the certificates and the old certificate is not in use, you can safely delete the certificate.
05-31-2023 04:30 AM
@patrickbyrne456305724 replacing the "admin" certificate will result in restarting the ISE services. Replacing the other certificates does not result in restarting the services. Obviously for the EAP certificate you need to ensure the clients trust the ISE certificate, so use the same CA to issue the certificate and you should be fine.
Here is a cisco guide to renew ISE certificates - https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html
Once you've replaced the certificates and the old certificate is not in use, you can safely delete the certificate.
05-31-2023 07:24 AM
Many thanks for response..If you add/import the new Certs to the Primary ISE node do they then automatically get onto the Secondary. Or, would you need to import onto Secondary first etc?
05-31-2023 07:57 AM
Step 7 |
(Optional) Check the services for which this certificate will be used in the Usage area. Changing the Admin usage certificate on a primary PAN restarts the services on all the other nodes. The system restarts one node at a time, after the primary PAN restarts. |
Only the admin certificate initiates a restart of the ISE services.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide