cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1481
Views
0
Helpful
1
Replies

System Certificates Backup/Restore

matthen
Cisco Employee
Cisco Employee

Are system certificates included in a configuration backup of ISE?  If so, what happens during a restore?  Are the existing system certificates on the target system deleted and replaced with the system certificates from the backup?

1 Accepted Solution

Accepted Solutions

Arne Bier
VIP
VIP

Yes they are.

You can only restore a config backup on a standalone node.  Once restored, you'll have the appropriate system cert that matches the hostname.  Let's say your old pan was ise01 and you had a system cert for that.  If int he deployment you also had ise02, ise03 with their own system certs, and if you restored the backup onto one of them, then I think ISE is clever enough to apply the appropriate system cert to the standalone node.

However, when you register additional nodes back into the deployment then those standalone nodes will know nothing about the PAN.  You'll have to prep each standalone with your PKI Trusted Certs and then the node's system certs prior to registering it with the PAN.   You could cheat and use self-signed certs but that's not cool.

View solution in original post

1 Reply 1

Arne Bier
VIP
VIP

Yes they are.

You can only restore a config backup on a standalone node.  Once restored, you'll have the appropriate system cert that matches the hostname.  Let's say your old pan was ise01 and you had a system cert for that.  If int he deployment you also had ise02, ise03 with their own system certs, and if you restored the backup onto one of them, then I think ISE is clever enough to apply the appropriate system cert to the standalone node.

However, when you register additional nodes back into the deployment then those standalone nodes will know nothing about the PAN.  You'll have to prep each standalone with your PKI Trusted Certs and then the node's system certs prior to registering it with the PAN.   You could cheat and use self-signed certs but that's not cool.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: