<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Certificate Revocation List in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106136#M146641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A few questions:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Are you using the same CA for each ISE?&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;MS Enterprise CA?&lt;/LI&gt;&lt;LI&gt;I presume these are all part of the same deployment?&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;You allow the Admin node to communicate with the DMZ nodes?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you find this information useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Dec 2012 01:40:11 GMT</pubDate>
    <dc:creator>jw.sl9</dc:creator>
    <dc:date>2012-12-06T01:40:11Z</dc:date>
    <item>
      <title>ISE Certificate Revocation List</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106135#M146607</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a split domain setup, with 8 ISE nodes on the inside network, and 2 nodes on a DMZ in a different DNS domain.&lt;/P&gt;&lt;P&gt;When we first set this up a few months ago, it turned out that there was a bug that didn't allow multiple domains, and we tested a workaround at the time, so I'm guessing it's not too common yet (recent code releases (patch 4 and 1.1.2) fixed this issue, but.....&lt;/P&gt;&lt;P&gt;I've configured a CRL for the CA certs from the internal domain.&lt;/P&gt;&lt;P&gt;The ISE's on the DMZ have nothing to do with the internal domain, so I wouldn't have expected them to be interested in the CRL which is associated with a certificate (and chain) used on internal ISE's only.&lt;/P&gt;&lt;P&gt;Unfortunately though the DMZ ISE's are also trying to get to the CRL URL which is not accessible from the DMZ, so flagging up masses of errors. Any way of stopping individual PSN's from trying to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incidentally, even though the timeout to retry the download is hours, the external nodes seem to be retrying every 2-4 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to delete 18000 alarms today, so wasn't too pleased to find that you can only delete alarms 100 at a time???????????????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106135#M146607</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2019-03-11T02:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Certificate Revocation List</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106136#M146641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A few questions:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Are you using the same CA for each ISE?&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;MS Enterprise CA?&lt;/LI&gt;&lt;LI&gt;I presume these are all part of the same deployment?&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;You allow the Admin node to communicate with the DMZ nodes?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you find this information useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 01:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106136#M146641</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-06T01:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Certificate Revocation List</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106137#M146668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The internal nodes all use the same CA. The problem seems to be that even though the DMZ nodes have no need for the certificate in question, they still attempt download of the CRL.&lt;BR /&gt;The DMZ nodes use an external CA for which no CRL is currently set up.&lt;BR /&gt;All one deployment, split domain.&lt;BR /&gt;Admin talking to PSN through firewall. That communication is fine, but no way will DMZ node be able to talk to the internal CA.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 00:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-revocation-list/m-p/2106137#M146668</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2012-12-17T00:29:03Z</dc:date>
    </item>
  </channel>
</rss>

