...
ISE is adding extra 6, 12 or 18 hours to nextUpdate date for CRL which causes outage with reason : 12515 EAP-TLS failed SSL/TLS handshake because of an expired CRL associated with a CA in the client certificates chain) Guess of added extra hours are - In 2022: 6 hours - In 2023: 12 hours - In 2024: 18 hours
using option Retrieve CRL before of expiration
check option Ignore that CRL if not yet valid or expired or let it download CRL before x hours of expiration that is more than added extra hours ( 6, 12 or 18 ). e.g. if added extra hours is 6 hours, it should be 7 hours or more hours.
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.