<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mobail certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740665#M488605</link>
    <description>&lt;P&gt;Are you asking for the cert that ISE presents to the supplicant, or do you mean the client (supplicant) cert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are some highlights for the ISE cert (purpose = EAP )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Subject Common Name: can be anything but don't put a wildcard in here (e.g.&amp;nbsp; *.mycompany.com) - it breaks Windows supplicants&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EKU (Extended Key Usage):&amp;nbsp;Server Authentication&lt;/P&gt;
&lt;P&gt;Encryption: RSA 2048 bits (don't need more than this) - avoid ECC for now - not many clients support it&lt;/P&gt;
&lt;P&gt;Signature: SHA256&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course the client has to trust the cert that ISE presents during the EAP negotiation.&amp;nbsp; How you achieve this is another discussion.&amp;nbsp; Either purchase a public CA issued cert for ISE, or issue the ISE cert via internal PKI.&amp;nbsp; But then then you need to push that PKI cert chain to all the clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is pretty well documented in the ISE Admin Guide&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2018 02:12:43 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2018-11-07T02:12:43Z</dc:date>
    <item>
      <title>mobail certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740286#M488601</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;I want to use eap-tls for wifi connection with ise.&lt;/P&gt;
&lt;P&gt;what is the cert temple that I need to use?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 16:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740286#M488601</guid>
      <dc:creator>vereduk</dc:creator>
      <dc:date>2018-11-06T16:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: mobail certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740665#M488605</link>
      <description>&lt;P&gt;Are you asking for the cert that ISE presents to the supplicant, or do you mean the client (supplicant) cert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are some highlights for the ISE cert (purpose = EAP )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Subject Common Name: can be anything but don't put a wildcard in here (e.g.&amp;nbsp; *.mycompany.com) - it breaks Windows supplicants&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EKU (Extended Key Usage):&amp;nbsp;Server Authentication&lt;/P&gt;
&lt;P&gt;Encryption: RSA 2048 bits (don't need more than this) - avoid ECC for now - not many clients support it&lt;/P&gt;
&lt;P&gt;Signature: SHA256&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course the client has to trust the cert that ISE presents during the EAP negotiation.&amp;nbsp; How you achieve this is another discussion.&amp;nbsp; Either purchase a public CA issued cert for ISE, or issue the ISE cert via internal PKI.&amp;nbsp; But then then you need to push that PKI cert chain to all the clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is pretty well documented in the ISE Admin Guide&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 02:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740665#M488605</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-11-07T02:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: mobail certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740766#M488608</link>
      <description>Adding to the above, here is the document which you can follow : &lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, your question is titled Mobail certificate and if you are looking for EAP-TLS with mobile devices, then you could potentially be looking at BYOD for which the documentation is here &lt;A href="https://community.cisco.com/t5/security-documents/ise-byod/ta-p/3641689" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-byod/ta-p/3641689&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Nov 2018 03:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mobail-certificate/m-p/3740766#M488608</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-11-07T03:44:59Z</dc:date>
    </item>
  </channel>
</rss>

