cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3165
Views
1
Helpful
3
Replies

Renew "Certificate Services Node CA" Certificate over internal CA

marcelma
Level 1
Level 1

I'm looking for a way to renew the "Certificate Services Node CA" certificate that was signed by the internal Root CA. 

The Node CA is expired but was not renewed by ise. I'm able to create a csr but can't find a way to sign it, except exporting and sign it with an external CA. 

Any help would be appreciated.

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

If the Node CA certificate is expired, it's likely the entire Root chain has also expired. You can generate a new Root CA chain from the Administration > System > Certificates > Certificate Management > Certificate Signing Requests > Generate Certificate Signing Requests (CSR) page by selecting the ISE Root CA usage.

Screen Shot 2021-07-13 at 10.56.38 am.png

View solution in original post

3 Replies 3

Greg Gibbs
Cisco Employee
Cisco Employee

If the Node CA certificate is expired, it's likely the entire Root chain has also expired. You can generate a new Root CA chain from the Administration > System > Certificates > Certificate Management > Certificate Signing Requests > Generate Certificate Signing Requests (CSR) page by selecting the ISE Root CA usage.

Screen Shot 2021-07-13 at 10.56.38 am.png

Thanks, this is working.

My Root CA is still valid for a few jears but as I'm unable to sign thenode CA csr the Root CA renewal is a good workaround as ise created every Sub-CA new. I can now just remove the old certificates. 

marinogr
Level 1
Level 1

This is working solution, thanks.

You need to "Enable Certificate Authority" if it is disabled.

Administration > System > Certificates > Certificate Authority > Internal CA Settings > Enable Certificate AuthorityISE-enableCA.jpg