01-17-2025 03:37 PM
Hello,
Our Default self-signed server certificates are about to expire, so I need to know if is possible to renew them manually editing them on this way without breaking the cluster.
Certificate to renew:
Deployment, 1 prim admin, 1 prim monitoring
ISE version 2.7
Thanks in advance
Solved! Go to Solution.
01-18-2025 04:33 AM
Yes you can renew that self-signed certificate by leveraging the "Renewal Period" feature. When you enable that tick box then you will have to define the period in which the certificate should be renewed before its expiry date.
01-17-2025 11:39 PM - edited 01-17-2025 11:40 PM
- FYI : https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html
https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897
M.
01-18-2025 02:35 AM
@victormanuelsolis refer to the ISE certificate renewal guide already provided. Bear in mind when you replace the "admin" certificate the ISE services will restart. Ideally you should use your internal CA to sign the certificates.
FYI, ISE 2.7 is End of Life and End of Support, you should look to upgrade asap. ISE 3.3 patch 4 is the current Cisco recommended version.
01-18-2025 04:33 AM
Yes you can renew that self-signed certificate by leveraging the "Renewal Period" feature. When you enable that tick box then you will have to define the period in which the certificate should be renewed before its expiry date.
01-24-2025 08:05 AM - edited 01-24-2025 08:05 AM
Thank for your answer, should I renew first the primary or secondary? take in count that we have different certificates for each box
01-25-2025 04:49 AM
You're welcome. Why different certificates? both nodes are in the same deployment right? when you configure the option to renew the self-signed certs it would configured from the primary PAN and it would apply to the deployment not the individual nodes. So, when you do it from there you should be good to go with both nodes.
01-25-2025 05:20 AM
thanks, I don't know why we have 2 different certificates, I received these boxes in this way, however I'll start with the renewal of the primary admin and hope it apply it to the secondary
01-25-2025 07:19 AM
Actually because they are self-signed certs it would make sense to have them different because each node would have generated its own certificate, but anyway, changing the renewal config would apply to both and you should be good with both of them.
01-27-2025 07:14 AM
Just FYI,
Certificates renewed from the primary admin node and it replicated to the secondary, only 5 minutes of downtime due the restart of ISE application for both boxes. Duration for the renewed certificates: 10 years
01-28-2025 01:12 AM
Thanks for sharing the outcome and glad to hear it worked as expected.
01-19-2025 09:52 AM
Hi @victormanuelsolis ,
please take a look at ISE - Queue Link Error, search for Generate Signing Requests (CSR).
Hope this helps !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide