cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4788
Views
6
Helpful
3
Replies

PxGrid Certificate renewal

Hello, 

 

I have pxgrid integration btw FMC and ISE

I see that the certificate is expired

I see that ISE is the CA

 

As I can understand I have to create a CSR for the FMC (externally and not in FMC) and sign it through ISE, right?

How will I submit the CSR in ISE in order to sign it?

 

Thanks and regards, 

Konstantinos

1 Accepted Solution

Accepted Solutions

@kostasthedelegate 

If you are using ISE as the CA to sign the pxgrid certificate you don't need to generate a CSR, you can create the signed certificate using the ISE certificate portal - the output will be the signed certificate, private key and signing chain, which can then import to the FMC.

 

https://community.cisco.com/t5/security-documents/how-to-configure-pxgrid-in-ise-production-environments-pxgrid-1/ta-p/3646330

https://www.ciscopress.com/articles/article.asp?p=2963461&seqNum=2

 

View solution in original post

3 Replies 3

@kostasthedelegate 

If you are using ISE as the CA to sign the pxgrid certificate you don't need to generate a CSR, you can create the signed certificate using the ISE certificate portal - the output will be the signed certificate, private key and signing chain, which can then import to the FMC.

 

https://community.cisco.com/t5/security-documents/how-to-configure-pxgrid-in-ise-production-environments-pxgrid-1/ta-p/3646330

https://www.ciscopress.com/articles/article.asp?p=2963461&seqNum=2

 

Thank you for the immediate answer

Yes the ISE is the CA 

As I understand the certificate portal is at this location Administration > pxGrid Services > Certificates

Correct, see figure 6-13 in the ciscopress link I provided.