12-13-2022 07:18 AM
I do have a TAC open, but want to see if anyone has an idea while I'm waiting.
So, we use a public COMODO cert for our portals. I just got the renewed cert and went to install it last weekend. With the new cert, all portals load with:
ise-t.whatever.com uses an unsupported protocol.
Solved! Go to Solution.
12-13-2022 08:50 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480
M.
12-13-2022 08:16 AM
- What error do you get in Firefox ?
M.
12-13-2022 08:36 AM
basically the same.
Error code: SSL_ERROR_NO_CYPHER_OVERLAP
12-13-2022 08:50 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480
M.
12-13-2022 09:44 AM - edited 12-13-2022 10:08 AM
Thanks, that seems to be the bug. weird part is I tried rebooting yesterday and still had the issue, but seems to be working today. Only difference is I added patch 5 to the test node.
I'm going to restore it back to patch 4 and see if rebooting still works, will tell me if I have to also install patch 5 on my production before it works or not.
12-26-2022 11:08 PM
@marce1000 wrote:
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480
Pls confirm how I can download expired certificate from Cisco.
12-26-2022 11:11 PM
Just want to download expired ccie security written exam certificate
12-13-2022 11:24 AM
ok, not crazy. On 3.1 patch 4, the reboot workaround does not work. Applying patch 5 and verifying that still works.
12-13-2022 11:47 AM
Ok, patch 5 kicked in the new cert, so it appears to be the bug, with the caveat of needing patch 5 for the workaround to work. Will have to fix production this weekend.
05-09-2023 10:26 AM
Hey Dustin, we're currently hit with the bug but on the report is only mentions we need to "reload ISE server". Do you know if this is all of the nodes? Just the PSNs?
Thanks
05-09-2023 10:37 AM - edited 05-09-2023 10:41 AM
If you are on patch 5+, I believe the reboot should work. without 5 reboot did not fix the issue. The issue is with renewal, so could also maybe regenerate a completely new cert, but not sure.
I would suspect all nodes, but we just have a 2 node deployment, so can't verify that myself.
05-30-2023 07:20 PM
I had the same issue, moved portal certificate to another cert(admin/default), then deleted old and new portal certs.
Now reloaded PSN's and then PAN. Now, imported the new certificate back. Then it took the new certificate and is working fine.
07-04-2024 02:56 AM
We had the same issue on ISE 3.2 Patch 4
Followed the same procedure as Sri:
Moved guest portal certificate group to the default
deleted old (and new) portal certificates
reboot PSN1 (show application status to check functionality, all running >> OK), reboot PSN2
Upload new guest portal certificates with a new group
Link new cert group to guest portal
02-18-2025 04:58 AM
Got same on ISE 3.2 patch 7. Will have to do it on maintenance window. How long, Cisco, you will be making buggy software?
Because instead of expanding your Department of Inclusivity or so, you'd better hire developers with proper skills.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide