cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2172
Views
0
Helpful
7
Replies

Renew SCEP RA certificate in ISE

robo0003c
Beginner
Beginner

Hi!

 

The RA certificate has been renewed in Active Directory due to it soon to be expired. Now I have to adjust the SCEP RA Profile in ISE, and I have some questions.

 

I am going to follow this guide: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200543-Renew-SCEP-RA-certificate-on-Windows-Ser.html

 

And if I understand correctly, I will have to create a new SCEP RA profile to download the new certificates to the ISE trust Certificate Store, and re-bind my certificate template to the new SCEP RA profile.

 

My question is, what am I suppose to do with the old SCEP RA profile? Just leave it be? I found that if I remove it, ISE will per auto clean up the Certificate Trust store for the whole cert chain used in the SCEP RA profile: "When a SCEP RA Profile is removed, the associated CA chain is also removed from the Trusted Certificates Store.". That would remove the RootCA used for all my EAP and Admin certs, so I do not want to do that. But I don't want to have expired certs in ISE trust store also (the RA certificates).

 

If I leave the old SCEP RA profile be, can I safely remove the old RA Certificates in the ISE Certificate Trust Store? So that I don't have any expired certs in my trust store. See attached image of the RA cert in ISE Trusted Certificates Store that I want gone:

 

ISE Trusted Certificates StoreISE Trusted Certificates Store

1 Accepted Solution

Accepted Solutions