cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
336
Views
0
Helpful
3
Replies

Overwrite when renewing ISE certificates

CCC3
Level 1
Level 1

If the same issuing authority only changed the expiration date when renewing the certificate of replication ISE, is it correct to delete and overwrite the existing certificate?

ISE version is 2.7.

And do 2.7 and 3.x work differently?

3 Replies 3

check this cisco slides

I know it for wildcard cert. renew but it can apply to all other cert.

Screenshot (156).pngScreenshot (157).pngScreenshot (158).png

Although it is based on the ISE installed on the VM, 2.7 confirmed that it was overwritten and the existing certificate was deleted

In 3.2, we have verified that the existing certificate is also left.

Of course, I tested it with the same certificate

I think it's the right move to get overwritten like the result in 2.7 but I'm also wondering if it's the difference between 3.x and 2.x.

Arne Bier
VIP
VIP

This is a common question and some time ago, Cisco added this banner below.  e.g. in ISE 3.3 they tell you it's permitted

ArneBier_0-1722299035555.png