<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE API - can default internal CA key size be changed? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-api-can-default-internal-ca-key-size-be-changed/m-p/3469114#M195</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it does not appear to be an option as of ISE 2.3:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="112499" alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/112499_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will submit this suggestion to the PM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Oct 2017 00:40:17 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2017-10-25T00:40:17Z</dc:date>
    <item>
      <title>ISE API - can default internal CA key size be changed?</title>
      <link>https://community.cisco.com/t5/network-security/ise-api-can-default-internal-ca-key-size-be-changed/m-p/3469113#M194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have used the End Points Certificate to successfully get a cert plus key, however the default root CA used to generate the client certificate (Certificate Services Endpoint Sub CA) has a key length of 4096 bits. Unfortunately our devices have a 2048-bit key limit on loaded certs - since we are using EAP-TLS the devices need to be loaded with both root cert and client cert. Is it possible to change the default root cert used to generate the client cert from the API POST call??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 21:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-api-can-default-internal-ca-key-size-be-changed/m-p/3469113#M194</guid>
      <dc:creator>kpeters011</dc:creator>
      <dc:date>2017-09-28T21:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE API - can default internal CA key size be changed?</title>
      <link>https://community.cisco.com/t5/network-security/ise-api-can-default-internal-ca-key-size-be-changed/m-p/3469114#M195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it does not appear to be an option as of ISE 2.3:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="112499" alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/112499_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will submit this suggestion to the PM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 00:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-api-can-default-internal-ca-key-size-be-changed/m-p/3469114#M195</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2017-10-25T00:40:17Z</dc:date>
    </item>
  </channel>
</rss>

