<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE pxGrid and Certificates question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591392#M508753</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;I have a few queries regarding integrating ISE with IPAM solution from Infoblox.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Since, certificates are pretty important to integrate ISE with other solutions using certificates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;I am going integrate the production instance of IPAM with my test instance of ISE here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;So, what is that, the certificates on IPAM are signed by Commodo, while certificates for ISE are signed by internal intermediate CA server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Earlier, I had done integration with self-signed certificates, but again those were in test labs, for this one the case is a little different.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;The question that I have now is that, if I import the Commodo root certificate and the IPAM application certificate to ISE trusted certificate store and vice versa for IPAM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Will that still work to allow authentication between ISE pxGrid and IPAM?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Or do I need to have the certificate signed from the CA in order for this integration to work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Any pointers or ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jul 2018 10:56:22 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2018-07-05T10:56:22Z</dc:date>
    <item>
      <title>ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591392#M508753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;I have a few queries regarding integrating ISE with IPAM solution from Infoblox.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Since, certificates are pretty important to integrate ISE with other solutions using certificates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;I am going integrate the production instance of IPAM with my test instance of ISE here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;So, what is that, the certificates on IPAM are signed by Commodo, while certificates for ISE are signed by internal intermediate CA server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Earlier, I had done integration with self-signed certificates, but again those were in test labs, for this one the case is a little different.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;The question that I have now is that, if I import the Commodo root certificate and the IPAM application certificate to ISE trusted certificate store and vice versa for IPAM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Will that still work to allow authentication between ISE pxGrid and IPAM?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Or do I need to have the certificate signed from the CA in order for this integration to work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Any pointers or ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 10:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591392#M508753</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-05T10:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591393#M508754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The certificate running the GUI has nothing to do with the certificate that will be used to join the pxGrid.&amp;nbsp; You should be running your pxGrid using the internal CA running on the ISE servers.&amp;nbsp; Then you issue a certificate/private key that will be used on Infoblox to join the grid.&amp;nbsp; You install that certificate/private key combination along with the ISE internal CA root cert into Infoblox when configuring the pxGrid connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 12:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591393#M508754</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-07-05T12:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591394#M508755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;If I get this correct, then this certificate here, that has only pxgird enabled for is the one that I need to export with the key to Infoblox?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;IMG alt="certificate.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118154_certificate.jpg" style="font-size: 10pt; height: 33px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Just doing the confirmation, since I am really not that good with certificates though….&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt;Or do I need to export the following that has authentication and other enabled on it to Infoblox?&lt;/SPAN&gt;&lt;SPAN style="font-family: 'Cambria',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="certificate.jpg" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/118155_certificate.jpg" style="height: 24px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Cambria, serif; font-size: 10pt;"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Cambria, serif; font-size: 10pt;"&gt;Dinesh&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 12:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591394#M508755</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-05T12:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591395#M508756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No under your pxGrid services in ISE you generate the cert/private key for Infoblox.  A screen shot is attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are doing this in Chrome the pop-up to download the .zip file may not work.  In the .zip file, when you get it, should be the Infoblox cert and private key in PEM format along with the ISE internal root cert.  There will also be the root cert for the Admin GUI, but Infoblox shouldn’t need that from what I am reading.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 12:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591395#M508756</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-07-05T12:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591396#M508757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, this is new for me and never had used this feature before as well...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I see that I select Generate Single certificate without signing request&lt;/P&gt;&lt;P&gt;And here at the common name, do I need to enter the CN of the ISE server or the Infoblox server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further then import these certificates in Infoblox and it should be good to subscribe to the pxGrid service on ISE, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591396#M508757</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-05T13:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591397#M508758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The common name can be whatever you want.  If you want to put the FQDN of the Infoblox in there that is fine.  You can use a generic CN like I showed in the screen shots.  This is how you get a certificate/private key to join pxGrid.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591397#M508758</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-07-05T13:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591398#M508759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick reply, I will go ahead and try this out and update the thread with results!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591398#M508759</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-05T13:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591399#M508760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is again one query though, I see that the bundle has also created .key certificate.&lt;/P&gt;&lt;P&gt;I had never used such a kind of certificate before, if possible can you direct me how to use it while importing it in Infoblox?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591399#M508760</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-05T13:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE pxGrid and Certificates question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591400#M508761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can’t use a certificate without a private key.  I think the Infoblox wants the cert and key in the same file.  Put them together in a file and import that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pxgrid-and-certificates-question/m-p/3591400#M508761</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-07-05T13:57:19Z</dc:date>
    </item>
  </channel>
</rss>

