08-01-2019 12:40 AM
Hi,
I have an issue where I receive alarm for the cert being revoked and the message just says cert was revoked by the administrator and doesn't have the username. It is difficult to track down who deleted which cert.
Is there a way to get those details? We are using ISE internal CA to authenticate users.
This is the message:
--------------------------------------
Alarm Name :
Certificate Revoked
Details :
Revoked ISE CA issued Certificate : server=XXX
Description :
Certificate issued to Endpoint by ISE CA is revoked by Administrator
Severity :
Warning
Suggested Actions :
A revoked endpoint certificate cannot be unrevoked or used for authentication
*** This message is generated by Cisco Identity Services Engine (ISE) ***
Sent By Host : XXX
----------------------------------------
Thanks
Solved! Go to Solution.
08-06-2019 10:42 AM
If a reason given during revocation, we may see it in the Issued Certificates page.
08-06-2019 10:42 AM
If a reason given during revocation, we may see it in the Issued Certificates page.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide