07-11-2024 05:49 AM
Dear all
In an ISE deployment with 4 ISE nodes (2 PAN and 2 PSN) we have qustions with Intermediate CA renewal
Here is our PKI infrastructure:
-MY-Root.CA (Root CA)
- Windows Endpoints have Clients certs used for EAP authentication signed by these 2 Issuing CA
- ISE nodes have all certs signed also by these Intermedaite CA
The 2 Intermediate CA are expiring in May 2025 and the customer has renewed them while keeping the Private Keys (Looks possible in Microsoft). So we have now 2 Intermediate CA with same private keys as before and different serial numbers
-MY-Root.CA (Root CA) (nothing changed)
We have updated the Intermediate CA in ISE Trusted Store with the new ones. As the private keys remain the same, new Intermediate certs replaced the former ones. And for now it looks that everything is working fine regarding the EAP authentication and ISE deployment.
We now need to renew ISE certs for Admin, EAP and PxGrid and I wonder if we are not in a bad situation where everything will brake (ISE deployment and EAP authentication).
Any recommandation? In which order renewing Admin / EAP certs on the nodes (PPAN first or SPAN or PSN?)
More globally how do you manage this Intermediate CA renewal?
Thanks
07-11-2024 02:26 PM
You're right about certificate hygiene in general - I have not seen a lot of industry guidance (best practices) about those Day 2 type of operations.
But I also don't foresee any issues with you renewing the Admin cert of an ISE node, where the cert is issued by one of the new Intermediate CAs. As long as your web browsers have that new intermediate installed in their Trust Store, then all should be good. Renewing admin cert will restart services. I think you should renew the admin BEFORE the EAP cert, to prove the theory (less can go wrong).
Your EAP clients must of course have the new Intermediate CA certs in their trust store BEFORE you renew the ISE EAP system certs. Renewing ISE EAP system certs does not restart services. It will replace the EAP system cert for the PSN that you are renewing.
Why was preserving the private keys of your previous Intermediate certs done? Isn't that one of the security reasons for updating certs?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide