10-20-2020 04:24 AM
Hello
On a two node ISE 2.7 patch 2 system I saw a strange error while generating a cert in the pxGrid Services screen.
The certificate was in fact generated! - but due to the error message I was unable to download the cert. I don't know any other way to get access to that cert (I can see the cert under the Internal CA Issued Certs)
Short of restarting the ISE node, I don't know what else to try? Anyone seen this before?
10-20-2020 09:39 PM
Hello Arne,
If certificate for PxGrid client was generated with CSR in PKCS8 format. If SAN field is configured either in CSR or while generating certificate. If not then try by adding SAN field and check if that resolves the issue.
10-20-2020 11:43 PM
Hi
Thanks I already tried that.
The CSR was created on an ISE node.
I was creating two CSRs for the EAP roles on the two PSNs. And the idea was to have the EAP cert signed by the ISE Internal CA, so that I can hand out the ISE Internal Root CA cert to clients. No matter which PSN is used, the client will trust both. This customer has no PKI, therefore it seemed that the ISE CA was ideal.
The first CSR was accepted by the pxGrid certificate generator and it produced a cert that I was able to bind to ISE01. But it's ISE02 that I am having issues with. I created another CSR just for ISE02 but each time I get this .zip error, and the cert is created (but I cannot access it) - all the fields look correct when I view the cert details.
The weird thing is that the cert is always generated correctly and I can see it in the issued Certificates list. It seems like a bug in the packaging of the .zip file. I have never seen such an error and I have created a lot of certs on the internal ISE CA.
I have also stopped and rebooted both nodes - made no difference - still same .zip error.
10-20-2020 11:39 PM
hi Arne
hopefully u have already resolved this issue, but isnt there "Export certicficate" element in "Internal CA issued"?
10-20-2020 11:58 PM
@Andrii Oliinyk - sadly not - I can view or revoke the cert. When I view, there are no further options. Not even a BASE64 format that I could copy and paste.
08-11-2021 07:27 AM
i have the issue , certificate chain was created correctly but the " zip " process keeps fail , and i am not unable to download it .
is there a way to do that with cli?
08-11-2021 04:08 PM
Certificates cannot be managed via the CLI. If you're having issues generating certificates from the internal CA for supported BYOD/pxGrid use cases, you might try another browser and regenerating the CA Root Chain from the Generate CSR menu.
If you're still having issues, I would suggest opening a TAC case.
10-22-2020 02:38 PM
Check if the 3-level certificate hierarchy can be traced to a single root CA on both nodes.
10-27-2020 05:35 PM
wow I hadn't thought of that - I will check - but ISE should not allow more than one Root CA to be in place.
08-13-2021 09:36 PM - edited 08-13-2021 09:44 PM
If the ISE admin server certificate is issued by ISE internal CA, then this is a known issue -- CSCvi85028
Or, it could be due to CSCvp30790
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide