cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
586
Views
5
Helpful
2
Replies

Renewing certificate on ISE 1.21 in High Availability configuration

richard.smock
Level 1
Level 1

Wondering if there will be a service disruption when I renew the certificates (not self signed, domain based CA), on Cisco ISE 1.21 running as Pri and secondary.

Should the secondary be renewed first or second?

2 Replies 2

d.friday
Level 4
Level 4

Hello,

I've renewed Certs on our  1.4 servers last year and experienced zero down time.  I did start with my secondary server just in case I ran into any issues.

here is the Cisco link for renewing certs http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116977-technote-ise-cert-00.html

I hope this helps .. 

Please rate this if you can

 

Thanks for the reply.

I actually renewed them yesterday evening and did not see any downtime either, due to HA on ISE. If we did not have HA, I would have seen about a 5 minute outage as the ISE services has to restart after installing the new certs for HTTPS use.

Review Cisco Networking for a $25 gift card