<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.1.4 Can't run multiple signed CA's in the store in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218869#M126626</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anytime. keep this thread updates if you face any further issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Jun 2013 09:24:30 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-06-08T09:24:30Z</dc:date>
    <item>
      <title>ISE 1.1.4 Can't run multiple signed CA's in the store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218864#M126427</link>
      <description>&lt;P&gt;Using Sha1 for Cisco 7925g and sha256 for data. Two separate CA's, one EnTrust (SHA1) the other Local Wondows CA (SHA256); ISE can only use one at a time to process a particular protocol (ie..EAP-TLS, HTTP, etc...)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a result we have to have a separate PSN just for Wireless and Wired VoIP (which can only hold SHA1 RSA1024).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else run into this issue? &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The box said 'Requires Windows XP or better'. So I installed LINUX...&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218864#M126427</guid>
      <dc:creator>desmanicholson</dc:creator>
      <dc:date>2019-03-11T03:30:56Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.4 Can't run multiple signed CA's in the store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218865#M126461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is correct that you can only have one Cert for EAP and one for HTTPS; this is the case for all 1.1.X versions of ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why don't you just use one Cert for all of your EAP functions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 06:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218865#M126461</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-06-06T06:37:41Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.4 Can't run multiple signed CA's in the store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218866#M126505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I guess you're using 2 different CA's becuase you want to use certificate signed with SHA256 RSA signature however IP phones 7925 doesn't support or work with SHA256 so you want to use SHA1 for phones only. We had this discussion in the below listed link: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2165566"&gt;https://supportforums.cisco.com/thread/2165566&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, ISE can use only one cert for eap chaining and one for https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 08:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218866#M126505</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-06T08:43:52Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.4 Can't run multiple signed CA's in the store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218867#M126561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response, unfortunately policy doesn't allow for mixed mode (ie..sha1 for 7925's and sha256) for data. since the 7900 series wired and 7925g wireless can run sha256 we had to find a 3rd party hosted pki solution. Spoke with a Cisco ISE Engineer and he verified the configurations aren't granular enough to be able to direct traffic to the proper cert and protocol. The one that's active is the one that will be used. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco 7925 wireless new model that can acept a sha256 isn't coming until 2014 so i've heard and now sure when the wired desktop units will be able to handle sha256. Kinda leaves you in a pickle when architecting because it adds 2 PSN's automatically for HA/DR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The box said 'Requires Windows XP or better'. So I installed LINUX...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 12:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218867#M126561</guid>
      <dc:creator>desmanicholson</dc:creator>
      <dc:date>2013-06-06T12:27:00Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.4 Can't run multiple signed CA's in the store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218868#M126592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is exactly correct..Thanks for the link, I will check it out...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The box said 'Requires Windows XP or better'. So I installed LINUX...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 12:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218868#M126592</guid>
      <dc:creator>desmanicholson</dc:creator>
      <dc:date>2013-06-06T12:27:35Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.4 Can't run multiple signed CA's in the store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218869#M126626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anytime. keep this thread updates if you face any further issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jun 2013 09:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-4-can-t-run-multiple-signed-ca-s-in-the-store/m-p/2218869#M126626</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-08T09:24:30Z</dc:date>
    </item>
  </channel>
</rss>

