05-03-2023 02:07 AM - edited 05-03-2023 03:02 AM
Hi all;
I am using ISE 3.1 Patch 5 in my production environment. For some reasons I want to enable "Allow SHA1 Ciphers" option. When I do that, the "Application Server" services caches and then restart automatically. I have seen this behavior in every ISE 3.1 installation...
Any ideas?
Thanks
Solved! Go to Solution.
05-03-2023 03:09 AM
- This could be considered normal behavior because the application services need to adjust according to the new setting(s) , meaning it should then be a one time event only related to changing the allowed ciphers (?)
M.
05-03-2023 03:44 PM - edited 05-03-2023 03:45 PM
I have not seen this issue and I've enabled the 'Allow SHA1 ciphers' option on both my lab and a customer ISE 3.1 deployment. The app server restarted fine on both.
When I change the setting, the GUI prompts with the following message so I'm not sure why didn't get any warning.
If you continue to see this issue and can replicate it easily, I would suggest opening a TAC case to investigate.
"Changing SHA1 cipher settings will cause the ISE application server to restart on all deployment ISE machines, are you sure you want to proceed?"
05-03-2023 03:09 AM
- This could be considered normal behavior because the application services need to adjust according to the new setting(s) , meaning it should then be a one time event only related to changing the allowed ciphers (?)
M.
05-03-2023 03:32 AM - edited 05-03-2023 03:33 AM
Thanks for your reply...
After I enable the "Allow SHA1 Ciphers" option and then save the configuration, the "Application Server" service goes down without any message to warn me. After some time that the service goes up, we can confirm that the configuration changes has not applied. Now, make the change again, the "Application Server" service goes down for the second time, but this time the changes applies successfully!
05-03-2023 03:38 AM
- How do you assert that it does not work on first attempt ?
M.
05-03-2023 03:57 AM
Because the check box beside the "Allow SHA1 Ciphers" option not selected, although I selected it on the first place.
05-03-2023 05:01 AM
- Make sure you are not suffering from browser caching effects and or verify initial attempt (setting) with another browser , for instance,
M.
05-03-2023 05:13 AM
Thanks for your reply...
I have checked this situation from 4 ISE deployments with various browsers, with exactly same result.
05-03-2023 10:03 AM
- Possibly a bug , upgrade to latest available patch release for ISE 3.1 , if it does not help raise a TAC case ,
M.
05-03-2023 03:44 PM - edited 05-03-2023 03:45 PM
I have not seen this issue and I've enabled the 'Allow SHA1 ciphers' option on both my lab and a customer ISE 3.1 deployment. The app server restarted fine on both.
When I change the setting, the GUI prompts with the following message so I'm not sure why didn't get any warning.
If you continue to see this issue and can replicate it easily, I would suggest opening a TAC case to investigate.
"Changing SHA1 cipher settings will cause the ISE application server to restart on all deployment ISE machines, are you sure you want to proceed?"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide