<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to renew EAP certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4010538#M454564</link>
    <description>While not a renewal per say, the easiest way is to generate a new CSR on the admin node of the deployment selecting either multi use or eap for its usage.   &lt;BR /&gt;&lt;BR /&gt;You accomplish this two ways depending on what you need.&lt;BR /&gt;1. If you only need a self signed eap cert, then you can generate a new one by clocking the "generate self signed certificate" button in the "system certificates" page.&lt;BR /&gt;&lt;BR /&gt;2. If you require a CA signed eap cert (probably more common), then you can do that by navigating to this page, and clicking the "generate certificate signing request" button and entering the information.&lt;BR /&gt;https://&amp;lt;your admin node ip or name&amp;gt;/admin/#administration/administration_system/administration_system_certificates/certificates_cert_mgmt/certificates_cert_mgmt_cert_signing_requests&lt;BR /&gt;&lt;BR /&gt;Here is a visual guide&lt;BR /&gt;&lt;A href="https://networkproguide.com/cisco-ise-24-certificate-install/" target="_blank"&gt;https://networkproguide.com/cisco-ise-24-certificate-install/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here is the Cisco admin guide steps&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#ID961" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#ID961&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Now keep in mind a very important thing.  If you are creating a new CSR, be very careful before using a new CN.  Endpoints may be set up to only trust the CN found within the certificate, and auth can fail if you change it.  It varies by environment, but you can use a non existent CN (ex. old node name), and the cert will be properly built so long as it also appears in the SAN field.</description>
    <pubDate>Mon, 13 Jan 2020 15:11:18 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2020-01-13T15:11:18Z</dc:date>
    <item>
      <title>How to renew EAP certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4010454#M454563</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this has been covered or not, but whats the best way to renew a certificate on ISE, it is used for EAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Bobby&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 13:09:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4010454#M454563</guid>
      <dc:creator>Bobby123</dc:creator>
      <dc:date>2020-01-13T13:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew EAP certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4010538#M454564</link>
      <description>While not a renewal per say, the easiest way is to generate a new CSR on the admin node of the deployment selecting either multi use or eap for its usage.   &lt;BR /&gt;&lt;BR /&gt;You accomplish this two ways depending on what you need.&lt;BR /&gt;1. If you only need a self signed eap cert, then you can generate a new one by clocking the "generate self signed certificate" button in the "system certificates" page.&lt;BR /&gt;&lt;BR /&gt;2. If you require a CA signed eap cert (probably more common), then you can do that by navigating to this page, and clicking the "generate certificate signing request" button and entering the information.&lt;BR /&gt;https://&amp;lt;your admin node ip or name&amp;gt;/admin/#administration/administration_system/administration_system_certificates/certificates_cert_mgmt/certificates_cert_mgmt_cert_signing_requests&lt;BR /&gt;&lt;BR /&gt;Here is a visual guide&lt;BR /&gt;&lt;A href="https://networkproguide.com/cisco-ise-24-certificate-install/" target="_blank"&gt;https://networkproguide.com/cisco-ise-24-certificate-install/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here is the Cisco admin guide steps&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#ID961" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#ID961&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Now keep in mind a very important thing.  If you are creating a new CSR, be very careful before using a new CN.  Endpoints may be set up to only trust the CN found within the certificate, and auth can fail if you change it.  It varies by environment, but you can use a non existent CN (ex. old node name), and the cert will be properly built so long as it also appears in the SAN field.</description>
      <pubDate>Mon, 13 Jan 2020 15:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4010538#M454564</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-01-13T15:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew EAP certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4011104#M454565</link>
      <description>&lt;P&gt;Hi Damien,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for that explanation and links, most helpful!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the post certificate renewal testing, we are trying to work out the best way to test one of the certificate renewals (say on the secondary ISE box), and create a test SSID which points only to that secondary ISE server for testing before we update the primary server, is this something which is workable?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also with this EAP authentication certificate, we are trying to work out what the best way is to see how it is working at present, we do not have more in terms of working knowledge of this (i.e. is it just used for our Corporate Wifi or is it used for other services).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this makes sense!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Bobby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 10:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4011104#M454565</guid>
      <dc:creator>Bobby123</dc:creator>
      <dc:date>2020-01-14T10:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew EAP certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4013030#M454566</link>
      <description>&lt;P&gt;Yes, WLC, for example, is able to have different sets of RADIUS servers for different WLANs (SSIDs).&lt;/P&gt;
&lt;P&gt;As long as you are able to keep unique subjects for the certificates (e.g. different O our OU values), you may have more than one certificate associated with one ISE node, just need to move the usage around. Other than that, test, test, and test!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 21:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-eap-certificate/m-p/4013030#M454566</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-01-16T21:39:42Z</dc:date>
    </item>
  </channel>
</rss>

