cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4056
Views
50
Helpful
9
Replies

ISE Internal Cert Generation Failed - Something went wrong with ZIP file

Arne Bier
VIP
VIP

Hello

 

On a two node ISE 2.7 patch 2 system I saw a strange error while generating a cert in the pxGrid Services screen.

 

pxGrid cert zip issie.PNG

 

The certificate was in fact generated! - but due to the error message I was unable to download the cert. I don't know any other way to get access to that cert (I can see the cert under the Internal CA Issued Certs) 

 

Short of restarting the ISE node, I don't know what else to try? Anyone seen this before?

9 Replies 9

poongarg
Cisco Employee
Cisco Employee

Hello Arne,

 

If certificate for PxGrid client was generated with CSR in PKCS8 format. If SAN field is configured either in CSR or while generating certificate. If not then try by adding SAN field and check if that resolves the issue.

Hi

 

Thanks I already tried that.

 

The CSR was created on an ISE node.

I was creating two CSRs for the EAP roles on the two PSNs. And the idea was to have the EAP cert signed by the ISE Internal CA, so that I can hand out the ISE Internal Root CA cert to clients. No matter which PSN is used, the client will trust both. This customer has no PKI, therefore it seemed that the ISE CA was ideal.

The first CSR was accepted by the pxGrid certificate generator and it produced a cert that I was able to bind to ISE01. But it's ISE02 that I am having issues with. I created another CSR just for ISE02 but each time I get this .zip error, and the cert is created (but I cannot access it) - all the fields look correct when I view the cert details.

The weird thing is that the cert is always generated correctly and I can see it in the issued Certificates list. It seems like a bug in the packaging of the .zip file.  I have never seen such an error and I have created a lot of certs on the internal ISE CA.

I have also stopped and rebooted both nodes - made no difference - still same .zip error.

 

hi Arne

hopefully u have already resolved this issue, but isnt there "Export certicficate" element in "Internal CA issued"?

@Andrii Oliinyk  - sadly not - I can view or revoke the cert. When I view, there are no further options. Not even a BASE64 format that  I could copy and paste.

 

issued.png

i have the issue , certificate chain was created correctly but the " zip " process keeps fail , and i am not unable to download it .

is there a way to do that with cli?

Certificates cannot be managed via the CLI. If you're having issues generating certificates from the internal CA for supported BYOD/pxGrid use cases, you might try another browser and regenerating the CA Root Chain from the Generate CSR menu.

If you're still having issues, I would suggest opening a TAC case.

Peter Koltl
Level 7
Level 7

Check if the 3-level certificate hierarchy can be traced to a single root CA on both nodes.

wow I hadn't thought of that - I will check - but ISE should not allow more than one Root CA to be in place.

hslai
Cisco Employee
Cisco Employee

If the ISE admin server certificate is issued by ISE internal CA, then this is a known issue -- CSCvi85028

Or, it could be due to CSCvp30790