cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6385
Views
9
Helpful
3
Replies

Renew HydrantID SSL ICA G2 Cisco ISE

Hello,

I'm looking for some help, the following certificate will expire soon, so I need to know how can renew it or should I wait until it expires or can I delete it in a safe way?

Certificate: HydrantID SSL ICA G2

CISCO ISE 2.7 patch 9

1 Accepted Solution

Accepted Solutions

KarthikeyanD
Level 1
Level 1

 

As per cisco team,  This cert not needed for the higher version. May be you can check with TAC for more detail

Trust Certificate: HydrantID SSL ICA G2

Functions the certificate had - ISE connected to Cisco.com via SSL to obtain binary and data updates for Posture and BYOD. On February 14th, 2018, Cisco renewed the certificate for that SSL connection. The new certificate has a root certificate signed by QuoVadis. Therefore, you can either let it expire or you can freely remove it if your ISE is version above 2.3.

 

You can also check this Field notice, where this exact change has been documented: https://www.cisco.com/c/en/us/support/docs/field-notices/701/fn70122.html In summary:

 

Since this certificate was used in ISE 2.3 to fix a specific issue connected with which is no longer present in future version, this certificate does not need renewal and can be either removed or left to expire.

View solution in original post

3 Replies 3

KarthikeyanD
Level 1
Level 1

 

As per cisco team,  This cert not needed for the higher version. May be you can check with TAC for more detail

Trust Certificate: HydrantID SSL ICA G2

Functions the certificate had - ISE connected to Cisco.com via SSL to obtain binary and data updates for Posture and BYOD. On February 14th, 2018, Cisco renewed the certificate for that SSL connection. The new certificate has a root certificate signed by QuoVadis. Therefore, you can either let it expire or you can freely remove it if your ISE is version above 2.3.

 

You can also check this Field notice, where this exact change has been documented: https://www.cisco.com/c/en/us/support/docs/field-notices/701/fn70122.html In summary:

 

Since this certificate was used in ISE 2.3 to fix a specific issue connected with which is no longer present in future version, this certificate does not need renewal and can be either removed or left to expire.

Thanks

Thank you for your response!