12-11-2024 08:15 AM - edited 12-11-2024 08:16 AM
We have ISE 2.4
ISE 1-01 one blade server ( admin / monitoring )
ISE 1-02 one blade server ( policy )
ISE 2-01 one blade server ( admin / monitoring )
ISE 2-02 one blade server ( policy )
ISE 2 was decommission and trying to put it back to cluster so we can do PAN failover
yes i know version 2.4 is old but what i have to work with until we upgrade
ISE 1 has the update certs so vaild
ISE 2 certs expired and invaild
ISE 2 was re-sync to AD and Should I try to resync the ISE 1 and ISE 2 before trying to update the expired certs on ISE 2
12-11-2024 08:38 AM
Synchronization will automatically happens between ISE 1 and 2. The certificate that was used before should work on ISE 2 as long as it has the same hostname and IP address if the IP is included into the cert SANs.
12-11-2024 08:43 AM
ISE 1 doesn't have the SAN certs of ISE 2.
when certs were renewal for ISE 1 it only SANs include only ISE 1 and not ISE 2
ISE 2 was in storage for 2 years 
12-11-2024 09:11 AM
I see. In this case you just need to go to ISE 2 and generate the new CSR and then issue the certificate from your PKI. This process can be after you added ISE 2 to the deployment. However, in that case when you try to add ISE 2 to the deployment you will get a pop up warning about ISE 2 selfsigned certificate. Once you approve it the addition to the deployment will go ahead. If you want to avoid this warning message then you can import the new cert in ISE 2 and then add it to the deployment. The cert needs to be associated to the admin usage in ISE 2.
12-11-2024 09:35 AM
I don't see option to when I login into ISE 2 web gui and CSR need to be done on ISE 1?
12-12-2024 01:31 AM
Probably you already added ISE 2 to the deployment? in that case yes the CSR would need to be generated in ISE 1. I don't believe you can leave the CN blank. Do you get any error when you try to generate the CSR? if so, could you please share the screenshot?
12-11-2024 11:56 AM
I have the CN conflict and it's the same name and changing OU or U doesn't do anything.
Can i leave CN blank and ise SAN and list everything?
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide