05-04-2011 09:23 PM - edited 02-21-2020 04:20 AM
I've just tried to install an SSL certificate from our internal issuing CA to overcome the certificate error when browsing to the NAC guest server. I can no longer browse to the NAC Guest server as there is a reported mismatch in the private key. Can someone please tell me how I can either replace the new certificate with the old one if it is backed up, using the CLI? Alternatively does anyone know how to generate a new localhost cert from the CLI?
Thanks in advance for your help,
Mike.
07-12-2011 04:06 AM
To uplaod a private key follow this...
If the private key and Cert don't match you will get numerous issues with the DB, I suggest disabling replication before doing any work relating to PKI.
Grev
07-12-2011 03:32 PM
Hi Grev,
Thanks for this. I ended up raising a TAC case and they directed me to this link. After getting the various cert locations and importing the cert it works fine from either CLI or GUI. If absolutely necessary you can use the openssl toolset to re-generage CSR but it's generally best to backup the original web server SSL cert before you start!
Thanks for the reply,
Mike.
01-17-2019 06:25 AM
Hi,
Could you guide me on how to renew existing SSL certificate on Cisco NGS.
Please confirm if following setps are correct
From the administration interface, select Server > SSL Setting
Create CSR
Download CSR
Upload new Certificate issue by CA team
Reboot server
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide