08-17-2012 08:20 AM - edited 03-10-2019 07:26 PM
Hi,
I have just installed the secondary ISE and did the followings, but when I try to join the primary node, I received the Cannot authenticate the primary ISE, please check the server or certificate and try again.
- promote the secondary from standalone to primary
- export self cert from the seconary
- import the cert to the primary
- try to add not on the secondary used both IP and host name with super admin user
One thing I have noticed that the instruction on the ISE 1.1.1 import cert on primary section mentioned:
but the Certificat Authority Certificates does not exist on the left pane. I choosed Certificate store instead
any suggestions?
Solved! Go to Solution.
08-17-2012 08:58 AM
Hi,
Did you set the secondary node to primary? You may have tried to register the node in the wrong direction. For a node to register with the primary node, the registration request must be initiated from the primary node.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-17-2012 08:37 AM
I've seen that order to be different on the cert guide aswell.
Make sure that the admin password matches
08-17-2012 08:39 AM
Yes. Admin password is match. I have also tested to using a different super admin user created on both system. none of them working
08-17-2012 08:41 AM
do you have both certs on the primary node as of right now?
if you go to
Administration > System > Certificates
choose Certificate Store
what do you see there?
.
08-17-2012 08:44 AM
Yes. I have two certs there, one is local/primary the other one is imported from the secondary
08-17-2012 08:49 AM
I'm sorry, you do or don't see two certs there?
08-17-2012 08:54 AM
I tried to add the cert from primary and imported it into the secondary. Run add note again, get different error:
Unable to register primary_host. Node is not a Standalone node.
08-17-2012 08:58 AM
Hi,
Did you set the secondary node to primary? You may have tried to register the node in the wrong direction. For a node to register with the primary node, the registration request must be initiated from the primary node.
Thanks,
Tarik Admani
*Please rate helpful posts*
08-17-2012 09:18 AM
Thanks, Tarik: that's It.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide