<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Certificate Authentication Without a CA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016555#M172641</link>
    <description>&lt;P&gt;I have a unique situation where I am trying to authenticate via certificates in an enviroment without a CA. I have a wildcard cert from a third party that I can place on the devices. I added the thrid party root CA in the local store on ISE but I am still using the self-signed cert from ISE in my local certs for EAP authentication. Is there a way to use a wildcard cert for device authentication or is there a way to export a cert from ISE that can be loaded on the end device fro authentication. Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:33:56 GMT</pubDate>
    <dc:creator>Nicholas Copeland</dc:creator>
    <dc:date>2019-03-11T02:33:56Z</dc:date>
    <item>
      <title>ISE Certificate Authentication Without a CA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016555#M172641</link>
      <description>&lt;P&gt;I have a unique situation where I am trying to authenticate via certificates in an enviroment without a CA. I have a wildcard cert from a third party that I can place on the devices. I added the thrid party root CA in the local store on ISE but I am still using the self-signed cert from ISE in my local certs for EAP authentication. Is there a way to use a wildcard cert for device authentication or is there a way to export a cert from ISE that can be loaded on the end device fro authentication. Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016555#M172641</guid>
      <dc:creator>Nicholas Copeland</dc:creator>
      <dc:date>2019-03-11T02:33:56Z</dc:date>
    </item>
    <item>
      <title>ISE Certificate Authentication Without a CA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016556#M172644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a side note when I use a wildcard cert I get an error that no private key is found when trying to authentictae to the ISE appliance. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 13:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016556#M172644</guid>
      <dc:creator>Nicholas Copeland</dc:creator>
      <dc:date>2012-09-19T13:02:38Z</dc:date>
    </item>
    <item>
      <title>ISE Certificate Authentication Without a CA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016557#M172657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please review the below link which might&amp;nbsp; be helpful on your concerns: &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_client_prov.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_client_prov.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 23:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016557#M172657</guid>
      <dc:creator>vikasyad</dc:creator>
      <dc:date>2013-05-29T23:05:16Z</dc:date>
    </item>
    <item>
      <title>ISE Certificate Authentication Without a CA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016558#M172670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Vikas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have since found the answer I was looking for. I talked with some of the guys in the BU and basically wildcard certs aren't supported on the end devices which make sense since it kind of eliminates the security aspect of certificate authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The guides you sent still require the use of an actual CA or SCEP server in order to get the certificates to the clients. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short I came up with a different solution that didn't use certificates.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 12:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016558#M172670</guid>
      <dc:creator>Nicholas Copeland</dc:creator>
      <dc:date>2013-05-30T12:27:40Z</dc:date>
    </item>
    <item>
      <title>ISE Certificate Authentication Without a CA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016559#M172690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Coming in a little late on this but my question was going to be: "What exactly is the end goal" For instance, were you looking to use EAP-TLS and if so then without a CA then you would probably need to look to something else. For instance, PEAP. However, I see that you have resolved your own issue which is great! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; Do you care to share with the rest of us what your solution was?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 00:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-without-a-ca/m-p/2016559#M172690</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-05-31T00:51:05Z</dc:date>
    </item>
  </channel>
</rss>

