<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017587#M291333</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is ok to use Apache you just need the correct OID enabled which is for server authentication. You can use the same cert for authentication and http web server, however the eap authentication server requirements are not as stringent on the hostname as the http management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also what are you using for the format when creating the CSR are you just using the CN-isefqdn, or did you follow the example here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_man_cert.html#wp1077292"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_man_cert.html#wp1077292&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Step 4 &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="5" /&gt;Enter&amp;nbsp; the certificate subject and the required key length. The certificate&amp;nbsp; subject is a distinguished name (DN) identifying the entity that is&amp;nbsp; associated with the certificate. The DN must include a common name&amp;nbsp; value. Elements of the distinguished name are: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132137"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;C = Country &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132226"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;S = Test State or Province &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132139"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;L = Test Locality (City) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132140"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;O = Organization Name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132141"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;OU = Organizational Unit Name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132142"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;CN = Common Name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132259"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;E = E-mail Address &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Sep 2012 17:53:39 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-09-05T17:53:39Z</dc:date>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017579#M291221</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im trying to get my head around using 3d party certificates with the ISE and I think I need some guidance here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a setup of 6 ISE nodes, 2xAdmin, 2xMonitoring and 2xPolicy.&lt;/P&gt;&lt;P&gt;All of these have the domain-name of abc.local.&lt;/P&gt;&lt;P&gt;I want to use MS-CHAPv2 and guest service without certifcate error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So do I need to enroll all of my six nodes with a 3d party CA? Or just 2xPolicy nodes?&lt;/P&gt;&lt;P&gt;I know the best solution would be all six but just to know if it is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I get around the problem with .local? I do not think it is possible to get a certificate with .local as a domain in FQDN.&lt;/P&gt;&lt;P&gt;Is SAN certificate usefull here? How would the look (still .local in CN..?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other things to consider in this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards &lt;/P&gt;&lt;P&gt; Mikael &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017579#M291221</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2019-03-11T02:29:30Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017580#M291222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can only ask a 3rd party CA a certificate for a valid and public domain that you own. Since "abc.local" isn't a valid public domain then the 3rd party CA can't generate the certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want a ".local" domain you can just create your certificates yourself by using Microsoft Certificate Authority for example, and then make all your domain PCs "trust" this domain by using Group Policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 20:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017580#M291222</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-09-04T20:22:38Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017581#M291224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about FQDN and the ISE, what I understand I do need to use &lt;EM&gt;hostname.abc.local&lt;/EM&gt;&amp;nbsp; in the CSR?&lt;/P&gt;&lt;P&gt;Based on ip domain-name and hostname from the ISE &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if I want a 3d party signing of this I need to change ip domain-name?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing somethinge here? &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation say:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: arial;"&gt;Same from the UG 1.1.1:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: arial;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;If you intend to use the certificate generated from this CSR for HTTPS communication (Management Interface), ensure that the CN value in the Certificate Subject is the FQDN of the node. Otherwise, you will not be able to select Management Interface when binding the generated certificate.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: arial;"&gt;From TS 2.1 How-To 04:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: arial;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;Note: &lt;/STRONG&gt;If you did not create the certificate signing request (CSR) with the same host name as the Cisco ISE server (or did not use the same domain name), then you will receive an error message. Delete the old CSR or simply change the host name and start again.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 04:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017581#M291224</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2012-09-05T04:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017582#M291226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct you need to issue the csr based on the host name currently configured for ise which is the fqdn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your issue is that public certificate authorities will not issue you a cert because you are using a .local and not a public domain like .com, .edu or .org to name a few.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to resolve your issue is to use a private Microsoft certificate authority, which is simple to configure. Or change your ise domain ame and use your company's public domain name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 04:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017582#M291226</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-05T04:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017583#M291238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And how about ip domain-name on ISE and joining a AD domain, do they have to match? &lt;/P&gt;&lt;P&gt;There are no suprise problem to change the domain name on ISE? &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 05:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017583#M291238</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2012-09-05T05:16:18Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017584#M291254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mikael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is a real good question, for all deployments I havent seen a condition where the ISE domain name is different then the Active Directory domain name that i joins to. I know that ISE creates a computer object in AD once its joined to AD and when joining AD it needs to be able to perform a forward and reverse lookup for its entry in DNS. My assumption is that it needs to be in the same domain space as AD but I can't confirm that for a fact. Let me do some research and I will let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 06:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017584#M291254</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-05T06:41:38Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017585#M291266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tarik &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a quick test yesterday with my Vmware ISE lab, I changed the domain name and joined the AD domain.&lt;/P&gt;&lt;P&gt;It did join. but what are the consequences... I did not look at any log or debug output&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 07:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017585#M291266</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2012-09-05T07:40:27Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017586#M291289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am doing third party certificates aswell, the built in CSR generation tool doesn't work as it has a problem with adding CN attributes ( for me it says no organization name has been included in CN subject when i try to enroll it to a third party signing tool).&lt;/P&gt;&lt;P&gt;I am trying to use the certs for PEAP authentication, I think you can't use the same cert for authentication and management at the same time.&lt;/P&gt;&lt;P&gt;Question to ask though: On godaddy enrollment it is asking me what platform is this for: Apache and all the other things, since this is for PEAP is there any particular platform that i need to use for the cert?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 16:34:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017586#M291289</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-09-05T16:34:09Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017587#M291333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is ok to use Apache you just need the correct OID enabled which is for server authentication. You can use the same cert for authentication and http web server, however the eap authentication server requirements are not as stringent on the hostname as the http management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also what are you using for the format when creating the CSR are you just using the CN-isefqdn, or did you follow the example here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_man_cert.html#wp1077292"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_man_cert.html#wp1077292&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Step 4 &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="5" /&gt;Enter&amp;nbsp; the certificate subject and the required key length. The certificate&amp;nbsp; subject is a distinguished name (DN) identifying the entity that is&amp;nbsp; associated with the certificate. The DN must include a common name&amp;nbsp; value. Elements of the distinguished name are: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132137"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;C = Country &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132226"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;S = Test State or Province &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132139"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;L = Test Locality (City) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132140"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;O = Organization Name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132141"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;OU = Organizational Unit Name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132142"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;CN = Common Name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1132259"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;E = E-mail Address &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 17:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017587#M291333</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-05T17:53:39Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017588#M291371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;now this is all over the place lol.&lt;/P&gt;&lt;P&gt;yes i did that and i even talked to TAC they said they recommend using openssl to genrate the csr and i did.&lt;/P&gt;&lt;P&gt;Anyway thanks for your help..&lt;/P&gt;&lt;P&gt;I'll have TAC deal with this I guess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 20:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017588#M291371</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-09-05T20:25:42Z</dc:date>
    </item>
    <item>
      <title>ISE and certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017589#M291424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;seems like a double post but i'm just gonna add it here incase someone ever looks for it as it has adequate tags&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alright, I've been able to create my own CA in win2008 and ubuntu server aswell ( I was so desperate about this cert thing on windows 7 where it popped up that terminate/connect error that i had to create all that)&lt;/P&gt;&lt;P&gt;Anyway the scenario is using third party cert.&lt;/P&gt;&lt;P&gt;**The domain name doesn't have to match ISE domain name for PEAP Authentication** (so i used my guest webpage ssl cert)&lt;/P&gt;&lt;P&gt;Now windows 7 computers that are a part of a domain/workgorup using native wireless client would still get that error no matter what, even if you add the root cert as a trusted authority in cert list and all that, even third party ones.&lt;/P&gt;&lt;P&gt;Seems like a windows7 bug and here is the workaround:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/2518158"&gt;http://support.microsoft.com/kb/2518158&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I just did that for root ca and intermediate ca from third party ca (goddady in my case) - I did test it with windows server ca and also with ubuntu server ca (yes i did test alot &lt;SPAN __jive_emoticon_name="silly"&gt;&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps someone as it was driving me crazy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 14:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-certificates/m-p/2017589#M291424</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-09-07T14:40:20Z</dc:date>
    </item>
  </channel>
</rss>

