<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE can not Import Server Certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/3319832#M179730</link>
    <description>&lt;P&gt;Can you clarify what you mean by, "&lt;SPAN&gt;Step 5: Bind the certificate to the signing request"? Note I am using ISE 2.3.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jan 2018 18:26:24 GMT</pubDate>
    <dc:creator>kevink707</dc:creator>
    <dc:date>2018-01-26T18:26:24Z</dc:date>
    <item>
      <title>ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/1994253#M179719</link>
      <description>&lt;P&gt;I want to use 802.1x EAP-TLS protocol authenticate client,then requested web server certificate from Microsoft 2003 CA server and saved it to my PC,&amp;nbsp; when I open local Certificates&amp;gt;Import Server&amp;nbsp; page in ISE , there is "Private Key File" item,but I don't know how generate this file.&lt;/P&gt;&lt;P&gt;In addition,after I Submit,ISE prompt "Unable to read certificate file - please be sure file is in PEM or DER format".&lt;/P&gt;&lt;P&gt;Anyone tell me how procedure I do,truly grateful.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/1994253#M179719</guid>
      <dc:creator>huang zhongwei</dc:creator>
      <dc:date>2019-03-11T02:25:42Z</dc:date>
    </item>
    <item>
      <title>ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/1994254#M179720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you generated the CSR on the ISE node locally, you are choosing the wrong option. Please use the "Bind CA Signed Certificate" option instead. The private key is generated already when you created the CSR on the ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as your 2nd question what are you doing to get this error? Are you generating a bogus private key file and trying to import this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 04:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/1994254#M179720</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-15T04:18:40Z</dc:date>
    </item>
    <item>
      <title>ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/1994255#M179726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Steps for configuring certificate in ISE &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1 :Download the CA’s certificate &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2 :Trust the CA in ISE a. In ISE, go to Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Certificates Authority Certificates &lt;/P&gt;&lt;P&gt;b. Add the CA certificate as a trusted certificate &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 3: Create a certificate signing request (CSR)&lt;/P&gt;&lt;P&gt;Go to Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Local Certificates, and click Add&lt;/P&gt;&lt;P&gt;b. Generate a certificate signing request&lt;/P&gt;&lt;P&gt;c. Export the CSR from Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Signing Requests&lt;/P&gt;&lt;P&gt;d. Once saved, open the .PEM file with notepad and copy the entire contents to the clipboard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 4: Submit the CSR to the CA for signing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 5: Bind the certificate to the signing request&lt;/P&gt;&lt;P&gt;a. In ISE, go to Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Local Certificates and add the certificate by binding the certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 6 :Confirm that the new ISE certificate is being used&lt;/P&gt;&lt;P&gt;a. Log out of ISE and close all browser windows&lt;/P&gt;&lt;P&gt;b. Reopen the browser and go to the ISE login page. Confirm that the browser is securing the https session using the new ISE certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 09:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/1994255#M179726</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2013-07-18T09:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/3319832#M179730</link>
      <description>&lt;P&gt;Can you clarify what you mean by, "&lt;SPAN&gt;Step 5: Bind the certificate to the signing request"? Note I am using ISE 2.3.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 18:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/3319832#M179730</guid>
      <dc:creator>kevink707</dc:creator>
      <dc:date>2018-01-26T18:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/3319848#M179733</link>
      <description>&lt;P&gt;I found the answer -- after you generate a CSR request you need to load the certificate on the "Certificate Signing Requests" page (by selecting Bind Certificate) rather than trying to import it as a new certificate on the "System Certificates" page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco could make this more intuitive.....&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 18:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/3319848#M179733</guid>
      <dc:creator>kevink707</dc:creator>
      <dc:date>2018-01-26T18:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4005307#M179735</link>
      <description>&lt;P&gt;good.&lt;/P&gt;&lt;P&gt;when I`m trying to do&amp;nbsp;&lt;SPAN&gt;Step 5: Bind the certificate to the signing request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;this error appear " &lt;STRONG&gt;Certificate path validation failed. make sure required Certificate chain is imported under Trusted Certificates&amp;nbsp;&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2020 11:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4005307#M179735</guid>
      <dc:creator>mohannad87</dc:creator>
      <dc:date>2020-01-01T11:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4005393#M179744</link>
      <description>You need to import the root and any intermediate certificates that are in the certificate chain of the signed / generated certificate.  &lt;BR /&gt;&lt;BR /&gt;You do this under the "Trusted Certificates" menu/page on the primary admin node.</description>
      <pubDate>Thu, 02 Jan 2020 03:54:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4005393#M179744</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-01-02T03:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4870248#M582727</link>
      <description>&lt;P&gt;My friend,&lt;/P&gt;&lt;P&gt;How can do it:&amp;nbsp;&lt;SPAN&gt;Step 4: Submit the CSR to the CA for signing?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am using 2.7 version ISE.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 23:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4870248#M582727</guid>
      <dc:creator>Analistaredes</dc:creator>
      <dc:date>2023-07-08T23:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE can not Import Server Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4870498#M582733</link>
      <description>&lt;P&gt;See the information and examples provided in &lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_blank" rel="noopener"&gt;How To Implement Digital Certificates in ISE&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is something additional you are having trouble with, please provide more detail on what help you require.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2023 22:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-can-not-import-server-certificate/m-p/4870498#M582733</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-07-09T22:03:32Z</dc:date>
    </item>
  </channel>
</rss>

