cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8327
Views
20
Helpful
4
Replies

OK to delete DST Root CA X3 Certificate Authority ?

Arne Bier
VIP
VIP

Hello

 

A lot of ISE systems will be reporting that the Trusted Certificate "DST Root CA X3 Certificate Authority" is going to be expiring soon. I believe this certificate is (or was) used by ISE to trust the connection with certain Cisco backend systems. 

 

I have not seen any official notices from Cisco - does anyone know if we can already delete this certificate? Once it's expired it's of no use - just causing alarms.

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

does anyone know if we can already delete this certificate? Once it's expired it's of no use - just causing alarms.

Yes, we can.

Expired certificates may cause ISE upgrade to fail.

View solution in original post

4 Replies 4

hslai
Cisco Employee
Cisco Employee

does anyone know if we can already delete this certificate? Once it's expired it's of no use - just causing alarms.

Yes, we can.

Expired certificates may cause ISE upgrade to fail.

thanks @hslai - I think it might be helpful to include a certificate removal function in ISE patches as soon as Cisco realises that this cert is no longer required. Some time back there was anothe cert that expired and there were many questions in the community about it.

Or perhaps a field notice or email or something. I subscribe to bug and patch updates and to be honest I stopped reading those because it's meaningless data to scroll through a list of defects - not knowing if any of this affects you or not.  But I would have deleted this certificate (and others) on the advice of Cisco, had I known about it.

So the certificate is not used at all? Or do the other certificates fulfill the functions of this certificate that will expire?

@ali.rodriguez It is now unused, I've deleted it off all the deployments I've been managing without any ill effects.