cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
188
Views
8
Helpful
5
Replies

Renew Default self-signed server certificate Cisco ISE 2.7

Hello,

Our Default self-signed server certificates are about to expire, so I need to know if is possible to renew them manually editing them on this way without breaking the cluster.

victormanuelsolis_0-1737156720835.png

Certificate to renew:

victormanuelsolis_1-1737156844960.png

Deployment, 1 prim admin, 1 prim monitoring

victormanuelsolis_2-1737156934508.png

ISE version 2.7

Thanks in advance

 

5 Replies 5

marce1000
Hall of Fame
Hall of Fame

 

   - FYI : https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html
             https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

@victormanuelsolis refer to the ISE certificate renewal guide already provided. Bear in mind when you replace the "admin" certificate the ISE services will restart. Ideally you should use your internal CA to sign the certificates.

FYI, ISE 2.7 is End of Life and End of Support, you should look to upgrade asap. ISE 3.3 patch 4 is the current Cisco recommended version.

Yes you can renew that self-signed certificate by leveraging the "Renewal Period" feature. When you enable that tick box then you will have to define the period in which the certificate should be renewed before its expiry date.

Thank for your answer, should I renew first the primary or secondary? take in count that we have different certificates for each box

Hi @victormanuelsolis ,

 please take a look at ISE - Queue Link Error, search for Generate Signing Requests (CSR).

 

Hope this helps !!!