06-07-2024 06:47 AM
Hello all,
I am experiencing this issue on one of my ISE PSN Servers running v3.1 patch 7.
The bug page says these are the work arounds:
Workaround: Use a different browser. Resign the cert or use a different cert that includes "Digital Signature, Non-Repudiation" as the Key Usage.
Ok, using a different browser, same error. (Used both Chrome and Edge, not permitted to use any other browsers).
What do they mean "Resign the cert or use a different cert that includes "Digital Signature, Non-Repudiation" as the Key Usage."???
I am an old school network engineer not a web guru nor a very proficient ISE administrator though I am learning fast. Is there a solid documentation that tells me solve this or another blog with the steps outlining a solution because some poor person had to solve this on their own??
Thank you!!
Solved! Go to Solution.
06-08-2024 02:17 PM
Hi there
As usual, badly written bug ID that doesn't offer much hope. I logged into CCO to read the "details" but there's not much to go on. Here's what I can tell you. When you make an ISE Admin cert, the CA that creates the cert for you, must use a template (e.g. in Microsoft Windows Server Certificate Authority) that includes "Digital signature" as the Key Usage. Here is a screenshot from Windows Server CA's template that can be used for any typical "Web Server" (like ISE Admin cert)
That's been working fine for since day 1. Non-repudiation doesn't even enter into the discussion.
Questions:
Check your ISE cert - click on the padlock in Firefox and click Connection Secure
Then click on More Information, View Certificate
When the bug ID refers to "resigning the cert", they should have said "revoke the cert" and re-issue a new cert that includes the Digital Signature in the Key Usage field. If you stick with the Windows Server CA basic template "web server" you can't go wrong.
06-08-2024 02:17 PM
Hi there
As usual, badly written bug ID that doesn't offer much hope. I logged into CCO to read the "details" but there's not much to go on. Here's what I can tell you. When you make an ISE Admin cert, the CA that creates the cert for you, must use a template (e.g. in Microsoft Windows Server Certificate Authority) that includes "Digital signature" as the Key Usage. Here is a screenshot from Windows Server CA's template that can be used for any typical "Web Server" (like ISE Admin cert)
That's been working fine for since day 1. Non-repudiation doesn't even enter into the discussion.
Questions:
Check your ISE cert - click on the padlock in Firefox and click Connection Secure
Then click on More Information, View Certificate
When the bug ID refers to "resigning the cert", they should have said "revoke the cert" and re-issue a new cert that includes the Digital Signature in the Key Usage field. If you stick with the Windows Server CA basic template "web server" you can't go wrong.
06-10-2024 06:16 AM
Hello Arne,
Let me give this a go and see if I can solve this.
Side Note: We are planning an upgrade to ISE v3.2 patch 6. We can't upgrade to v3.3 patch 2 since our WLC 9800s are running v17.9.5 which hasn't been approved for use with ISE v3.3 yet as per Cisco documentation & TAC Case. They are testing/getting ready to test this combination as per TAC.
So, with that in mind, if I can't fix this then the upgrade will do it for me. Thank you for your reply, sir!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide