<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Integration with PEAP (Server side Cert) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026858#M220236</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CSR should be in PEM format, my assumption is that you used the default SHA-256 to generate the request, try using SHA-1 and that should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Oct 2012 05:07:53 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-10-22T05:07:53Z</dc:date>
    <item>
      <title>ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026855#M220191</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;We are currently evaluating ISE and I am stuck with the PEAP authentication (with Server side Cert).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our current setup consists of two 5508 controllers, 30+ access point. For authentication we are using PEAP with (server side Cert). We have an IAS server which is also acting as a CA server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using Cisco’s NAM as a supplicant on Windows XP &amp;amp; 7 workstations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to use ISE for authentication. I would like to use PEAP with Server side Cert (similar setup like IAS). I want ISE to perform the same function in addition to profiling etc..... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to integrate ISE with Active Directory but could not get it working with PEAP (server side Cert). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone done this before? If yes then can you share step by step instructions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also like to know if they used Microsoft’s CA server or Open SSL CA server or a third party CA server (Go Daddy, VeriSign etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you we ISE as a CA server just the way we used Microsoft’s IAS Server as a CA Server? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance &lt;/P&gt;&lt;P&gt;Ds&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026855#M220191</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2019-03-11T02:42:15Z</dc:date>
    </item>
    <item>
      <title>ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026856#M220206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Answers inline:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Our&amp;nbsp; current setup consists of two 5508 controllers, 30+ access point. For&amp;nbsp; authentication we are using PEAP with (server side Cert). We have an IAS&amp;nbsp; server which is also acting as a CA server. &lt;STRONG&gt;IAS and CA are two seperate roles that a windows server can run, just wanted to clear that up, that the IAS services still need a cert imported/signed for it to present a cert for PEAP server side certificate.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using Cisco’s NAM as a supplicant on Windows XP &amp;amp; 7 workstations. &lt;STRONG&gt;Good choice much better to control across different platforms&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; would like to use ISE for authentication. I would like to use PEAP with&amp;nbsp; Server side Cert (similar setup like IAS). I want ISE to perform the&amp;nbsp; same function in addition to profiling etc..... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to integrate ISE with Active Directory but could not get it working with PEAP (server side Cert). &lt;STRONG&gt;You will need to generate a CSR from the ISE server (Go to Administration &amp;gt; Certificates &amp;gt; Local Server Cert.. &amp;gt; Add &amp;gt; Generate CSR &amp;gt; then go to the CSR container and export your CSR&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone done this before? If yes then can you share step by step instructions? &lt;STRONG&gt;This response should answer your question&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; would also like to know if they used Microsoft’s CA server or Open SSL&amp;nbsp; CA server or a third party CA server (Go Daddy, VeriSign etc.) &lt;STRONG&gt;Who is "they" if you are authenticating users within an enterprise where laptops are issues by the corporation then you should save the cost and use your internal CA (windows), if this is a campus environment (BYOD) then you should get a public CA.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you we ISE as a CA server just the way we used Microsoft’s IAS Server as a CA Server? &lt;STRONG&gt;No.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance &lt;/P&gt;&lt;P&gt;Ds&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 02:34:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026856#M220206</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-22T02:34:20Z</dc:date>
    </item>
    <item>
      <title>ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026857#M220225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to generate the CSR from ISE.&amp;nbsp; After generating CSR I exported the cert in a temp folder. &lt;/P&gt;&lt;P&gt;I have also installed a Microsoft CA server (windows 2008 R2) so the CA server can issue Cert to ISE. The problem I am having is CSR is in .PEM format and Microsoft does not understand that format. Therefore I used online tools to convert the cert in .DER or PKCS#12. But Microsoft doesn’t like it. &lt;/P&gt;&lt;P&gt;Do you have any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ds &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 04:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026857#M220225</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-10-22T04:43:00Z</dc:date>
    </item>
    <item>
      <title>ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026858#M220236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CSR should be in PEM format, my assumption is that you used the default SHA-256 to generate the request, try using SHA-1 and that should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 05:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026858#M220236</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-22T05:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026859#M220262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco recommends using 3rd party software to generate CRS, like openssl I did it and it worked fine.&lt;/P&gt;&lt;P&gt;I used godaddy cert (Go daddy glass 2), which on apple devices comes up as UNVERIFIED, so I don't know what's the point of buying it for PEAP (it does work for http ssl though).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For windows machines that are joined to a workgroup there is still a problem when users try to connect to a SSID,&lt;/P&gt;&lt;P&gt;eventhough you have a root cert as trusted on the machine, it comes up as unverified.&lt;/P&gt;&lt;P&gt;Seems like a windows7 bug, here is an article from windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A href="http://support.microsoft.com/kb/2518158" rel="nofollow"&gt;http://support.microsoft.com/kb/2518158&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/295663" rel="nofollow"&gt;http://support.microsoft.com/kb/295663&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 14:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026859#M220262</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-10-22T14:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026860#M220290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Tarik !!!&amp;nbsp; Selecting SHA-1 instead of SHA-256 did the trick. One step closer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have step by step instructions to complete the CSR on Windows 2008 R2. Should we use the GUI method or use the IIS interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;edondurguti: I am ok to use Open SSL as a CA server and then submit the CSR to open SSL. Do you have written instructions to perform that task?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 19:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026860#M220290</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-10-22T19:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026861#M220318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well not exactly but i used parts from here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00806e367a.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00806e367a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you're good with what you done so far.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 19:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026861#M220318</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-10-22T19:32:31Z</dc:date>
    </item>
    <item>
      <title>ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026862#M220357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks edondurguti. I ended up submitting my CSR to DegiCert and it worked like a champ. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 19:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026862#M220357</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-10-23T19:59:08Z</dc:date>
    </item>
    <item>
      <title>ISE Integration with PEAP (Server side Cert)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026863#M220368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am unable to do machine and user authentication using PEAP. I am not sure what is wrong with my Authorization policies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ISE side it says authenticated (user and machine separately) but on the client side. It says limited or no connectivity. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using AnyConnect 3.1 on the client side as a supplicant&lt;/P&gt;&lt;P&gt;ISE version is 1.1.1 with patch 3.&lt;/P&gt;&lt;P&gt;WLC version is 7.2.103.0&lt;/P&gt;&lt;P&gt;Is there a compatibility issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 17:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-integration-with-peap-server-side-cert/m-p/2026863#M220368</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-10-31T17:42:10Z</dc:date>
    </item>
  </channel>
</rss>

