I have to introduce a new CA to the Organisation. In doing so I have two Machine Certs on my Laptop. One is the existing (OLD CA-01) and the new CA (CA-02).
On my Cisco ISE, I have both Root Certs of CA-01 and CA-02. What are the Criteria for "Use Simple Certificate Selection"?
In my understanding, it does group all the Certs according to the SAN and use the one with the latest expiry date.
Issue: When I delete my cert of CA-02 from the laptop that is the latest but then it still takes this cert for authentication. I have doubled checked the Cisco ISE logs, and it shows the name of the CA-02 cert.
After deleting both certs from the laptop it then still authenticates with the latest cert that is of CA-02. I have tested this on different laptops and the behavior does not change.
The confusion is, is it a Windows 10/11 bug or a certificate stuck in buffer or something? I also double-checked the Windows registry entry and after deleting it cert entry is not there. How to clear the certificate buffer if there is any?
Or any other advise??
Please help!
Regards, B