Cisco Cisco Identity Services Engine Express License Bundle Troubleshooting Guide

Page of 11
openssl x509 −in certificate.der −inform DER −outform PEM −out certificate.pem
Troubleshoot
There is currently no specific troubleshooting information available for this configuration.
Conclusion
Because you can install a new certificate on the ISE before it is active, Cisco recommends that you install the
new certificate before the old certificate expires. This overlap period between the old certificate expiration
date and the new certificate start date gives you time to renew certificates and plan their installation with little
or no downtime. Once the new certificate enters its valid date range, enable the EAP and/or HTTPS protocol.
Remember, if you enable HTTPS, there will be a service restart.
Updated: Jun 26, 2015
Document ID: 116977