<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.2 and WildCard Cert in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279282#M125311</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in the process of a new ISE deployment and have come across an isue with the wildcard cert and generating the CSR. I have also spoken with TAC and the are telling me the same thing I am reading in the Cisco DOC so am missing somethng somewhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am being told that ISE REQUIRED a FQDN for the CN and then you place the wildcard in teh SAN. So far two different CA providers are tellng me I&amp;nbsp; cannot generate a wild card certificate this way. How has anyone else gotten this to work. When I pressed TAC I was told it would probably work with the CN containing the wildcard but there have been reported issues specifically with microsoft clients.&amp;nbsp; Considering the cost of the cert is several hundred dollars I do not want to be wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brent &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Feb 2014 22:26:03 GMT</pubDate>
    <dc:creator>bberry</dc:creator>
    <dc:date>2014-02-18T22:26:03Z</dc:date>
    <item>
      <title>ISE 1.2 and WildCard Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279277#M125306</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;i"ve found a great post from Aaron Woland about how to make/install/use Wildcard certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.networkworld.com/community/blog/what-are-wildcard-certificates-and-how-do-i-use-them-ciscos-ise" target="_blank"&gt;http://www.networkworld.com/community/blog/what-are-wildcard-certificates-and-how-do-i-use-them-ciscos-ise&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but there is something that was not answered by his post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can i use WildCard cert to register node to an ISE deployement? Aka adding a Monitor only node to a admin only node&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create CSR, receiving Cert from CA, adding CA root, binding cert to CA root then exporting key, then importin on Mon node then try to register mon node? my first test didnt go well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input would be appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279277#M125306</guid>
      <dc:creator>eric.lessard</dc:creator>
      <dc:date>2019-03-11T03:53:00Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 and WildCard Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279278#M125307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;new ISE 1.2 does support Wildcard cert server. Please refer to below discussion as well&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2233071"&gt;https://supportforums.cisco.com/thread/2233071&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 07:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279278#M125307</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2013-09-11T07:24:47Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 and WildCard Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279279#M125308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A wildcard certificate uses a wildcard notation&amp;nbsp; (an asterisk and period before the domain name) and allows the&amp;nbsp; certificate to be shared across multiple hosts in an organization. ISE 1.2 support the use of wildcard certificate. For more information over configuration you can see the below link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_man_cert.html#wp1171325"&gt;http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_man_cert.html#wp1171325&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 17:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279279#M125308</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-09-11T17:39:32Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 and WildCard Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279280#M125309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No you should not be able to register the node in ISE by wildcard certi, because for my knowledge certificates are used for secure the link between node and the ISE device or network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Sep 2013 00:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279280#M125309</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-09-19T00:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 and WildCard Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279281#M125310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with what you are saying but it seems that your statement contradicts the write up on the Cisco user guide for 1.2, there are no limitations and one of the benefits stated by the doc is that you can use wildcard certs as a cost saving measure which will allow you to install the cert on all ISE nodes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have a corporate wildcard certificate and I will attempt to register two nodes together and see what the result is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the true benefit of a wildcard cert is where the CN is *.domain.com, you should not have to generate a CSR where the CN=iseblah.domain.com with a SAN of *.domain.com, I do not think that is a cost effective wildcard cert since the CN has the fqdn of the ISE node.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_man_cert.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_man_cert.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Sep 2013 05:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279281#M125310</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-09-19T05:13:42Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 and WildCard Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279282#M125311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in the process of a new ISE deployment and have come across an isue with the wildcard cert and generating the CSR. I have also spoken with TAC and the are telling me the same thing I am reading in the Cisco DOC so am missing somethng somewhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am being told that ISE REQUIRED a FQDN for the CN and then you place the wildcard in teh SAN. So far two different CA providers are tellng me I&amp;nbsp; cannot generate a wild card certificate this way. How has anyone else gotten this to work. When I pressed TAC I was told it would probably work with the CN containing the wildcard but there have been reported issues specifically with microsoft clients.&amp;nbsp; Considering the cost of the cert is several hundred dollars I do not want to be wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brent &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 22:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279282#M125311</guid>
      <dc:creator>bberry</dc:creator>
      <dc:date>2014-02-18T22:26:03Z</dc:date>
    </item>
    <item>
      <title>Hi Tarik, Did you have any</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279283#M125312</link>
      <description>&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you have any luck with this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got a customer with ISE 1.2.198 and has provided me with a wildcard cert which has the following details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN=*.abc.local&lt;/P&gt;&lt;P&gt;SAN=DNS Name ise1.abc.local&lt;/P&gt;&lt;P&gt;SAN=DNS Name ise2.abc.local&lt;/P&gt;&lt;P&gt;SAN=Another 15 or so DNS entries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer is using AD EAP-PEAP(MSCHAPv2) authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to simply bind this to each of the ISE nodes (2) as appose to the standard CSR and separate cert for each?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 18:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-wildcard-cert/m-p/2279283#M125312</guid>
      <dc:creator>Nick Lavender</dc:creator>
      <dc:date>2015-10-27T18:35:29Z</dc:date>
    </item>
  </channel>
</rss>

