<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using different CAs for different devices' cert based authentication via ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440179#M510273</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp; it is possible.&lt;/P&gt;&lt;P&gt;first of all you need to import the Root CA (issuer CA) into ISE ( under Trusted Certificate page)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need create two rules under policy for &lt;SPAN style="font-size: 10.0pt; font-family: Arial, sans-serif;"&gt;AD CA for users' mobile device&amp;nbsp; and &lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;IoT devices.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;ISE has several attributes to differentiate&amp;nbsp; these two flows&amp;nbsp; ( e.g. BYODRegistration flag&amp;nbsp;&amp;nbsp; for BYOD flow&amp;nbsp; or using Certificate (Issuer CA) attributes,device location or group ...)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;here is an example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/116844_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;YYes&lt;/DIV&gt;&lt;DIV&gt;HTH,&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 May 2018 09:08:24 GMT</pubDate>
    <dc:creator>smashash</dc:creator>
    <dc:date>2018-05-02T09:08:24Z</dc:date>
    <item>
      <title>Using different CAs for different devices' cert based authentication via ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440177#M510271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;Hi there, Customer has two separate sets of devices that they want to implement certificated based authentication via ISE. One is their users' mobile devices (BYOD scenario). The other is their IoT devices (Yes, these devices are cert ready). They want to use two different CAs &lt;SPAN style="font-family: Arial, sans-serif;"&gt;(AD CA for users' mobile device while ISE CA for IoT device). Is this possible and how to do that? Thanks. - William&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 08:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440177#M510271</guid>
      <dc:creator>wingai</dc:creator>
      <dc:date>2018-05-02T08:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using different CAs for different devices' cert based authentication via ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440178#M510272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is ,look here &lt;A href="https://community.cisco.com/docs/DOC-64014"&gt;ISE Certificate Authority (CA)&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 08:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440178#M510272</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-05-02T08:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using different CAs for different devices' cert based authentication via ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440179#M510273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp; it is possible.&lt;/P&gt;&lt;P&gt;first of all you need to import the Root CA (issuer CA) into ISE ( under Trusted Certificate page)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need create two rules under policy for &lt;SPAN style="font-size: 10.0pt; font-family: Arial, sans-serif;"&gt;AD CA for users' mobile device&amp;nbsp; and &lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;IoT devices.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;ISE has several attributes to differentiate&amp;nbsp; these two flows&amp;nbsp; ( e.g. BYODRegistration flag&amp;nbsp;&amp;nbsp; for BYOD flow&amp;nbsp; or using Certificate (Issuer CA) attributes,device location or group ...)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;here is an example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/116844_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;YYes&lt;/DIV&gt;&lt;DIV&gt;HTH,&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 09:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-different-cas-for-different-devices-cert-based/m-p/3440179#M510273</guid>
      <dc:creator>smashash</dc:creator>
      <dc:date>2018-05-02T09:08:24Z</dc:date>
    </item>
  </channel>
</rss>

