Note
This module is part of the cisco.ise collection (version 2.10.0).
You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install cisco.ise. You need further requirements to be able to use this module, see Requirements for details.
To use it in a playbook, specify: cisco.ise.trusted_certificate.
Note
The cisco.ise collection is considered unmaintained and will be removed from Ansible 12. Once removed, you can still install the collection manually with ansible-galaxy collection install cisco.ise. See the discussion thread for more information.
New in cisco.ise 1.0.0
Note
This module has a corresponding action plugin.
The below requirements are needed on the host that executes this module.
Parameter | Comments |
|---|---|
authenticateBeforeCRLReceived boolean | Switch to enable or disable CRL verification if CRL is not received. Choices:
|
automaticCRLUpdate boolean | Switch to enable or disable automatic CRL update. Choices:
|
automaticCRLUpdatePeriod integer | Automatic CRL update period. |
automaticCRLUpdateUnits string | Unit of time for automatic CRL update. |
crlDistributionUrl string | CRL Distribution URL. |
crlDownloadFailureRetries integer | If CRL download fails, wait time before retry. |
crlDownloadFailureRetriesUnits string | Unit of time before retry if CRL download fails. |
description string | Description for trust certificate. |
downloadCRL boolean | Switch to enable or disable download of CRL. Choices:
|
enableOCSPValidation boolean | Switch to enable or disable OCSP Validation. Choices:
|
enableServerIdentityCheck boolean | Switch to enable or disable verification if HTTPS or LDAP server certificate name fits the configured server URL. Choices:
|
id string | Id path parameter. ID of the trust certificate. |
ignoreCRLExpiration boolean | Switch to enable or disable ignore CRL expiration. Choices:
|
ise_debug boolean | Flag for Identity Services Engine SDK to enable debugging. Choices:
|
ise_hostname string / required | The Identity Services Engine hostname. |
ise_password string / required | The Identity Services Engine password to authenticate. |
ise_single_request_timeout integer added in cisco.ise 3.0.0 | Timeout (in seconds) for RESTful HTTP requests. Default: |
ise_username string / required | The Identity Services Engine username to authenticate. |
ise_uses_api_gateway boolean added in cisco.ise 1.1.0 | Flag that informs the SDK whether to use the Identity Services Engine’s API Gateway to send requests. If it is true, it uses the ISE’s API Gateway and sends requests to https://{{ise_hostname}}. If it is false, it sends the requests to https://{{ise_hostname}}:{{port}}, where the port value depends on the Service used (ERS, Mnt, UI, PxGrid). Choices:
|
ise_uses_csrf_token boolean added in cisco.ise 3.0.0 | Flag that informs the SDK whether we send the CSRF token to ISE’s ERS APIs. If it is True, the SDK assumes that your ISE CSRF Check is enabled. If it is True, it assumes you need the SDK to manage the CSRF token automatically for you. Choices:
|
ise_verify boolean | Flag to enable or disable SSL certificate verification. Choices:
|
ise_version string | Informs the SDK which version of Identity Services Engine to use. Default: |
ise_wait_on_rate_limit boolean | Flag for Identity Services Engine SDK to enable automatic rate-limit handling. Choices:
|
name string | Friendly name of the certificate. |
nonAutomaticCRLUpdatePeriod integer | Non automatic CRL update period. |
nonAutomaticCRLUpdateUnits string | Unit of time of non automatic CRL update. |
rejectIfNoStatusFromOCSP boolean | Switch to reject certificate if there is no status from OCSP. Choices:
|
rejectIfUnreachableFromOCSP boolean | Switch to reject certificate if unreachable from OCSP. Choices:
|
selectedOCSPService string | Name of selected OCSP Service. |
status string | Trusted Certificate’s status. |
trustForCertificateBasedAdminAuth boolean | Trust for Certificate based Admin authentication. Choices:
|
trustForCiscoServicesAuth boolean | Trust for authentication of Cisco Services. Choices:
|
trustForClientAuth boolean | Trust for client authentication and Syslog. Choices:
|
trustForIseAuth boolean | Trust for authentication within Cisco ISE. Choices:
|
Note
check_mode
See also
Complete reference of the Certificates API.
- name: Update by id
cisco.ise.trusted_certificate:
ise_hostname: "{{ise_hostname}}"
ise_username: "{{ise_username}}"
ise_password: "{{ise_password}}"
ise_verify: "{{ise_verify}}"
state: present
authenticateBeforeCRLReceived: true
automaticCRLUpdate: true
automaticCRLUpdatePeriod: 0
automaticCRLUpdateUnits: string
crlDistributionUrl: string
crlDownloadFailureRetries: 0
crlDownloadFailureRetriesUnits: string
description: string
downloadCRL: true
enableOCSPValidation: true
enableServerIdentityCheck: true
id: string
ignoreCRLExpiration: true
name: string
nonAutomaticCRLUpdatePeriod: 0
nonAutomaticCRLUpdateUnits: string
rejectIfNoStatusFromOCSP: true
rejectIfUnreachableFromOCSP: true
selectedOCSPService: string
status: string
trustForCertificateBasedAdminAuth: true
trustForCiscoServicesAuth: true
trustForClientAuth: true
trustForIseAuth: true
- name: Delete by id
cisco.ise.trusted_certificate:
ise_hostname: "{{ise_hostname}}"
ise_username: "{{ise_username}}"
ise_password: "{{ise_password}}"
ise_verify: "{{ise_verify}}"
state: absent
id: string
Common return values are documented here, the following are the fields unique to this module:
Key | Description |
|---|---|
ise_response dictionary | A dictionary or list with the response returned by the Cisco ISE Python SDK Returned: always Sample: |
ise_update_response dictionary added in cisco.ise 1.1.0 | A dictionary or list with the response returned by the Cisco ISE Python SDK Returned: always Sample: |
© 2012–2018 Michael DeHaan
© 2018–2025 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/cisco/ise/trusted_certificate_module.html