<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic certificate template for ISE CSR in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023667#M163143</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are going to use an inline node in your deployment, then my suggestions (along with experience) is to use a template that has the EKU for both client authentication and server authentication. The documentation clearly states this in the 1.1.1 release notes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to generate this type of cert then your best bet is to clone the Computer Template and allow web enrollment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Oct 2012 02:42:36 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-10-22T02:42:36Z</dc:date>
    <item>
      <title>certificate template for ISE CSR</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023666#M163139</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know about these on ISE CSR case. My business requreiment is &lt;/P&gt;&lt;P&gt;case 1: one primary node register one secondary node&lt;/P&gt;&lt;P&gt;case 2: one primary node register one inline posture node&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a enterprise CA running on window server 2008 R2. so i not intend to use any self-signed certificate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;quesiton&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. what is the certificate template should i use when i try to submit my CSR request? For both case&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. For both case end result, how should the local certificate and certificate store look like (ISE running on VER1.1.1)? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. should i do any convert on the microsfot based certificate in .cer extention to .pem, using openSSL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Million Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023666#M163139</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2019-03-11T02:42:01Z</dc:date>
    </item>
    <item>
      <title>certificate template for ISE CSR</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023667#M163143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are going to use an inline node in your deployment, then my suggestions (along with experience) is to use a template that has the EKU for both client authentication and server authentication. The documentation clearly states this in the 1.1.1 release notes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to generate this type of cert then your best bet is to clone the Computer Template and allow web enrollment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 02:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023667#M163143</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-22T02:42:36Z</dc:date>
    </item>
    <item>
      <title>certificate template for ISE CSR</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023668#M163147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your statement is it mean that both Primary node and Inline Posture node need to use the certificate template that has the EKU for both client authenticatio and server authentication? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i am sure that there's no computer to be select at the web enrollment, when i trying to submit the request at \certsrv.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If what if i able to use web server template to have both EKU select on the extention, would it be able to be use? As i fulfill the requirement of EKU for both client authenticaiton and server authetnicaiton. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore,&amp;nbsp; i found this statement from Cisco documentation &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_ipep_deploy.html#wp1110248"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_ipep_deploy.html#wp1110248&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it mentioned:&lt;/P&gt;&lt;P&gt;The following combinations are recommended for the Administration certificate:&lt;/P&gt;&lt;P&gt;– Both EKU attributes should be disabled, if both EKU attributes are disabled in the Inline Posture certificate, or both EKU attributes should be enabled, if the server attribute is enabled in the Inline Posture certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following combinations are recommended for the Inline Posture certificate:&lt;/P&gt;&lt;P&gt; –Both EKU attributes should be disabled, or both should be enabled, or the server attribute alone should be enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am really confused now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;looking forward on your reply..thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 03:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-template-for-ise-csr/m-p/2023668#M163147</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2012-10-22T03:10:04Z</dc:date>
    </item>
  </channel>
</rss>

