<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificates and private keys in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trouble-adding-wildcard-cert/m-p/2953849#M38573</link>
    <description>&lt;P&gt;Certificates and private keys should both be in PEM format. Those are the ones that begin and end with lines like:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;-----END CERTIFICATE-----&lt;/PRE&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;-----BEGIN PRIVATE KEY-----&lt;BR /&gt;-----END PRIVATE KEY-----&lt;/PRE&gt;
&lt;P&gt;...with a whole lot of ASCII text in between them. You can verify by opening them in a text editor. The extension doesn't really matter as long as the file contents are plain ASCII text delimited properly.&lt;/P&gt;
&lt;P&gt;With those in hand, you can validate that a given key is the right one for a given certificate using openssl (or if you trust it, a webified interface that does the same thing: &lt;A href="https://www.sslshopper.com/certificate-key-matcher.html" target="_blank"&gt;https://www.sslshopper.com/certificate-key-matcher.html&lt;/A&gt; )&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2016 18:56:42 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-08-25T18:56:42Z</dc:date>
    <item>
      <title>trouble adding wildcard cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-adding-wildcard-cert/m-p/2953848#M38572</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ise 2.1&lt;/P&gt;
&lt;P&gt;i'm trying to add a wildcard cert. was told i would need to get an exported cert and key from the non-ise server that was used to get the wildcard cert.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i received 3 files: the ca cert (ca.crt), the wildcard cert (abc.crt), and the key (def.rtf)&lt;/P&gt;
&lt;P&gt;i added the ca.crt to ise ok in the trusted certificate section.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i then tried to import the system cert (abc.crt) along w/ the private key, but i'm getting errors "private key validation failed"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1 - am i going about this the right way?&lt;/P&gt;
&lt;P&gt;2 - is the .rtf file for the key the issue and if so - how can i convert it&lt;/P&gt;
&lt;P&gt;3 - does it matter that the key is actually from a different server?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-adding-wildcard-cert/m-p/2953848#M38572</guid>
      <dc:creator>moody</dc:creator>
      <dc:date>2019-03-11T07:01:47Z</dc:date>
    </item>
    <item>
      <title>Certificates and private keys</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-adding-wildcard-cert/m-p/2953849#M38573</link>
      <description>&lt;P&gt;Certificates and private keys should both be in PEM format. Those are the ones that begin and end with lines like:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;-----END CERTIFICATE-----&lt;/PRE&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;-----BEGIN PRIVATE KEY-----&lt;BR /&gt;-----END PRIVATE KEY-----&lt;/PRE&gt;
&lt;P&gt;...with a whole lot of ASCII text in between them. You can verify by opening them in a text editor. The extension doesn't really matter as long as the file contents are plain ASCII text delimited properly.&lt;/P&gt;
&lt;P&gt;With those in hand, you can validate that a given key is the right one for a given certificate using openssl (or if you trust it, a webified interface that does the same thing: &lt;A href="https://www.sslshopper.com/certificate-key-matcher.html" target="_blank"&gt;https://www.sslshopper.com/certificate-key-matcher.html&lt;/A&gt; )&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 18:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-adding-wildcard-cert/m-p/2953849#M38573</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-08-25T18:56:42Z</dc:date>
    </item>
  </channel>
</rss>

