04-13-2020 09:11 PM
Hello, We are on ISE 2.2 patch 16.
I am trying to delete one of our expiring internal certificate in trusted store. We have another one (new one) installed with same common name.
ISE wont let me delete the old one due to another cert that has the same common name.
Have you encountered the same issue before and do we know a work around to this issue?
04-14-2020 12:01 AM
04-14-2020 06:58 AM
thanks for the info.I went and opened a tac case.
Since you were not able to delete the trusted cert , Did you just let the certificate expire since you have the new one installed anyway?
If i understand correctly, since we have the new one installed and the trusted cert is only being used to validate ise server certificates there should be no impact once the old one expires.
04-14-2020 06:18 PM
04-14-2020 12:21 AM - edited 04-14-2020 12:22 AM
From the problem description, its seems you hitting this bug : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy36667/?rfs=iqvred
Details:
Symptom:
On ISE 2.0 it is not possible to delete certificate with duplicated common name even if it is not refrenced anywhere on ISE.
Conditions:
1. ISE 2.0
2. Two certificates with same common name in trusted store.
3. Try to delete one of them.
The Work around mentioned here is:
1. Remove template, scep and ldap references for the certificates.
2. Restart ISE services.
3. Remove one of the certificates.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide