<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Certs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047029#M23324</link>
    <description>&lt;P&gt;Hi CSC,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to get my head around the workings of Certificates within ISE as I wasn't the one who set the cert side of things up.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have our own internal PKI with machine and user certificates pushed out globally.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see the following within ISE which have been setup already.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;System Certs&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Trusted Certs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Under System Certs I have e.g &lt;EM&gt;"Cert 1"&lt;/EM&gt; which has various SAN entries -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;DNS Name: ise.company.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: authentication.company.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: wifi.company.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: ise-01.company.corp&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: ise-02.company.corp&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Usage - Admin, EAP Authentication&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Under Trusted Certs, there are various -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Our Root CA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Machine Cert&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;User Cert&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These are both configured for the following usage -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Trust for authentication within ISE&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Trust for client authentication and Syslog&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Trust for authentication of Cisco Services&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now my query is - What are each of these certificates used for and when?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;When using wired 802.1x for example for Corporate PCs/Users and I want to use EAP-TLS (machines and users already have certs) - Does ISE check the client presented certs against the "Trusted Certs"?&lt;/P&gt;
&lt;P&gt;When would the system cert be used that has all the SAN fields? This one also says it has EAP Auth usage.&lt;/P&gt;
&lt;P&gt;Any easy to understand info welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Really just want to know what certs would be used when using machine/user auth if using EAP-TLS&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:35:07 GMT</pubDate>
    <dc:creator>GRANT3779</dc:creator>
    <dc:date>2019-03-11T07:35:07Z</dc:date>
    <item>
      <title>ISE Certs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047029#M23324</link>
      <description>&lt;P&gt;Hi CSC,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to get my head around the workings of Certificates within ISE as I wasn't the one who set the cert side of things up.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have our own internal PKI with machine and user certificates pushed out globally.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see the following within ISE which have been setup already.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;System Certs&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Trusted Certs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Under System Certs I have e.g &lt;EM&gt;"Cert 1"&lt;/EM&gt; which has various SAN entries -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;DNS Name: ise.company.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: authentication.company.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: wifi.company.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: ise-01.company.corp&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DNS Name: ise-02.company.corp&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Usage - Admin, EAP Authentication&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Under Trusted Certs, there are various -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Our Root CA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Machine Cert&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;User Cert&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These are both configured for the following usage -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Trust for authentication within ISE&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Trust for client authentication and Syslog&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Trust for authentication of Cisco Services&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now my query is - What are each of these certificates used for and when?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;When using wired 802.1x for example for Corporate PCs/Users and I want to use EAP-TLS (machines and users already have certs) - Does ISE check the client presented certs against the "Trusted Certs"?&lt;/P&gt;
&lt;P&gt;When would the system cert be used that has all the SAN fields? This one also says it has EAP Auth usage.&lt;/P&gt;
&lt;P&gt;Any easy to understand info welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Really just want to know what certs would be used when using machine/user auth if using EAP-TLS&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047029#M23324</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-03-11T07:35:07Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047030#M23325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll try to answer your question in a simple way.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your cert1 is your ISE certificate used in the certification profile to authenticate (validate) certificates from your users and devices for EAP-TLS authentication. As per your input it has the admin feature that means it's used when you're accessing your ISE through https to not have the standard message"not trusted" website.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The different SAN address used when accessing ISE through https for admin, guest, sponsor or other portals using the fqdn and not IP. If ip isn't part of the certificate value, you should have the message not trusted website when accessing ISE by using ip instead of name.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The trusted certificate are used to validate all presented certificates (root and subordinate certificates). &amp;nbsp;You'll have all public certification authority and you should have your internal root ca and subordinate ca.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this is clear enough.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2017 01:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047030#M23325</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-04-02T01:34:05Z</dc:date>
    </item>
    <item>
      <title>Thanks Francesco,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047031#M23327</link>
      <description>&lt;P&gt;Thanks Francesco,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Managed to get EAP-TLS working successfully.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 17:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certs/m-p/3047031#M23327</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2017-04-05T17:20:57Z</dc:date>
    </item>
  </channel>
</rss>

