<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE usage of  “subject-serial number” / &amp;quot;certificates serial number as identity&amp;quot; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601537#M520537</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;The following gui is under External Identity Sources -&amp;gt; Certificate Authentication Profile. We would like to use the certificates serial number as identity, but the only option I see is “subject – serial number” (see below). It is my understanding that “subject-serial number” does not make sense to our PKI guys (I think that terminology is invalid in their view). We thought maybe it meant the certificates serial number which is what we want, but when I configured it, ISE failed saying the user information couldn’t be retrieved from the certificate. This would make sense if it’s trying to pull it out of the subject field, which is what I think it’s probably doing based on the gui, but the PKI guys would like to know what is “subject – serial number” and is it really a valid thing? Also, is there a way to use the certificate’s serial number as “user” identity to query ldap?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Oct 2017 15:10:21 GMT</pubDate>
    <dc:creator>jideji</dc:creator>
    <dc:date>2017-10-24T15:10:21Z</dc:date>
    <item>
      <title>ISE usage of  “subject-serial number” / "certificates serial number as identity"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601537#M520537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; font-size: 12pt;"&gt;The following gui is under External Identity Sources -&amp;gt; Certificate Authentication Profile. We would like to use the certificates serial number as identity, but the only option I see is “subject – serial number” (see below). It is my understanding that “subject-serial number” does not make sense to our PKI guys (I think that terminology is invalid in their view). We thought maybe it meant the certificates serial number which is what we want, but when I configured it, ISE failed saying the user information couldn’t be retrieved from the certificate. This would make sense if it’s trying to pull it out of the subject field, which is what I think it’s probably doing based on the gui, but the PKI guys would like to know what is “subject – serial number” and is it really a valid thing? Also, is there a way to use the certificate’s serial number as “user” identity to query ldap?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 15:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601537#M520537</guid>
      <dc:creator>jideji</dc:creator>
      <dc:date>2017-10-24T15:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE usage of  “subject-serial number” / "certificates serial number as identity"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601538#M520538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ISE dictionary CERTIFICATE has three serial numbers (attached a screenshot from ISE 2.3 conditions studio):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="112478" alt="Screen Shot 2017-10-23 at 9.50.40 PM.png" class="image-1 jive-image" height="200" src="/legacyfs/online/fusion/112478_Screen Shot 2017-10-23 at 9.50.40 PM.png" style="height: 199.52402745995423px; width: 346px;" width="346" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt;And, &lt;/SPAN&gt;&lt;A href="https://community.letsencrypt.org/t/certificates-with-serialnumber-in-subject/11891" style="font-family: Helvetica; font-size: 12px;"&gt;Certificates with serialNumber in subject - Server - Let's Encrypt Community Support&lt;/A&gt;&lt;SPAN style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt; shows that it possible to have the serial number as part of the “Subject”. Our engineering team confirmed that certificate serial number and subject serial number fields are independent. Only the one as part of &lt;STRONG&gt;Subject&lt;/STRONG&gt; line will be chosen and used in ISE cert auth profile&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt;The "subject - serial number” very likely differing from the serial number of the certificate issued by the CA. See examples below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://knowledge.symantec.com/support/ssl-certificates-support/index?page=content&amp;amp;actp=CROSSLINK&amp;amp;id=SO18140#Subject"&gt;What extensions and details are included in a SSL certificate? | Symantec&lt;/A&gt; —&amp;gt; Subject: &lt;SPAN style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;EM&gt;Serial Number (Business Registration Number)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.ietf.org/mail-archive/web/pkix/current/msg14588.html"&gt;Re: "Subject Alternative Name" v/s "Subject/Serial Number”&lt;/A&gt;—&amp;gt; Swedish national identity number.&lt;P&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 15:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601538#M520538</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-10-24T15:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE usage of  “subject-serial number” / "certificates serial number as identity"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601539#M520539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 20:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-usage-of-subject-serial-number-quot-certificates-serial/m-p/3601539#M520539</guid>
      <dc:creator>jideji</dc:creator>
      <dc:date>2017-10-26T20:21:09Z</dc:date>
    </item>
  </channel>
</rss>

