<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and Admin Certificate - why Client Auth EKU warning during import? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542618#M520763</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I imported a new cert into my ISE 2.2 nodes for the Admin usage.&lt;/P&gt;&lt;P&gt;I am able to browse to the web page of those PSN's just fine and it's loading the new cert.&lt;/P&gt;&lt;P&gt;Below is a subsection of the cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;X509v3 extensions:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; X509v3 Key Usage: critical&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Digital Signature, Key Encipherment&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.3.6.1.4.1.311.21.7: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;X509v3 Extended Key Usage: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG style="color: #ff6600;"&gt;TLS Web Server Authentication&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.3.6.1.4.1.311.21.10:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I imported the cert, I got the error below:&amp;nbsp; why is this EKU relevant for the Admin usage?&amp;nbsp; Or is this just a nag message?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-AU; mso-bidi-font-family: 'Times New Roman'; font-size: 11pt; mso-ansi-language: EN-AU; mso-fareast-theme-font: minor-latin; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;"&gt;&lt;IMG class="image-1 jive-image" height="125" src="https://community.cisco.com/legacyfs/online/fusion/111985_pastedImage_5.png" style="max-height: 900px; max-width: 1200px;" width="444" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-AU; mso-bidi-font-family: 'Times New Roman'; font-size: 11pt; mso-ansi-language: EN-AU; mso-fareast-theme-font: minor-latin; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;"&gt;If I assign that same certificate to the EAP usage, will EAP-TLS not work?&amp;nbsp; I seem to remember that the Client Authentication has to be present in the ISE cert for the purposes of EAP-TLS.&amp;nbsp; For EAP-PEAP this is not required because the client doesn't present a client certificate to the AAA server.&amp;nbsp; So in that case the warning should only appear if I attempt to apply the cert to the generic 'EAP usage'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Oct 2017 04:27:04 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2017-10-16T04:27:04Z</dc:date>
    <item>
      <title>ISE and Admin Certificate - why Client Auth EKU warning during import?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542618#M520763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I imported a new cert into my ISE 2.2 nodes for the Admin usage.&lt;/P&gt;&lt;P&gt;I am able to browse to the web page of those PSN's just fine and it's loading the new cert.&lt;/P&gt;&lt;P&gt;Below is a subsection of the cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;X509v3 extensions:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; X509v3 Key Usage: critical&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Digital Signature, Key Encipherment&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.3.6.1.4.1.311.21.7: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;X509v3 Extended Key Usage: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG style="color: #ff6600;"&gt;TLS Web Server Authentication&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.3.6.1.4.1.311.21.10:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I imported the cert, I got the error below:&amp;nbsp; why is this EKU relevant for the Admin usage?&amp;nbsp; Or is this just a nag message?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-AU; mso-bidi-font-family: 'Times New Roman'; font-size: 11pt; mso-ansi-language: EN-AU; mso-fareast-theme-font: minor-latin; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;"&gt;&lt;IMG class="image-1 jive-image" height="125" src="https://community.cisco.com/legacyfs/online/fusion/111985_pastedImage_5.png" style="max-height: 900px; max-width: 1200px;" width="444" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-AU; mso-bidi-font-family: 'Times New Roman'; font-size: 11pt; mso-ansi-language: EN-AU; mso-fareast-theme-font: minor-latin; font-family: 'Calibri',sans-serif; mso-fareast-font-family: Calibri;"&gt;If I assign that same certificate to the EAP usage, will EAP-TLS not work?&amp;nbsp; I seem to remember that the Client Authentication has to be present in the ISE cert for the purposes of EAP-TLS.&amp;nbsp; For EAP-PEAP this is not required because the client doesn't present a client certificate to the AAA server.&amp;nbsp; So in that case the warning should only appear if I attempt to apply the cert to the generic 'EAP usage'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 04:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542618#M520763</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-16T04:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Admin Certificate - why Client Auth EKU warning during import?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542619#M520765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, it's just a nag message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An ISE system certificate can potentially be used for client authentications; e.g. pxGrid subscriptions or connecting to an external HTTPS or LDAPS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For EAP usage in general, an ISE system certificate does not require client authentication in EKU. Only endpoint certificates do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 06:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542619#M520765</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-10-16T06:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Admin Certificate - why Client Auth EKU warning during import?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542620#M520767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks - now I think I finally understood it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 11:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-admin-certificate-why-client-auth-eku-warning-during/m-p/3542620#M520767</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-16T11:02:47Z</dc:date>
    </item>
  </channel>
</rss>

