<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE as SCEP server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599537#M524254</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hsing-Tsu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will it support another ISE ?&lt;/P&gt;&lt;P&gt;I just want to test the SCEP functionality&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to add one ISE server as SCEP server to another ISE but thats failing too.. Not sure if this would work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ultimately we would want to have as SCEP to MDM server. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108435_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/108436_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Jun 2017 19:00:29 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2017-06-19T19:00:29Z</dc:date>
    <item>
      <title>ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599535#M524252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone implemented ISE as a SCEP server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to enroll a cert into switch to test scep functionality in ISE but I cannot make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE SCEP URL&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108385_pastedImage_3.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;crypto pki trustpoint ISEPSN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;enrollment url &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://usnjise03.svlab.local:9090/auth/caservice/pkiclient.exe" rel="nofollow" target="_blank"&gt;http://usnjise03.svlab.local:9090/auth/caservice/pkiclient.exe&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;revocation-check crl&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;rsakeypair scep&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;crypto pki authenticate ISEPSN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am receiving an error after the above switch commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;% Error in receiving Certificate Authority certificate: status = FAIL, cert length = 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2017 18:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599535#M524252</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-06-16T18:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599536#M524253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE internal CA/SCEP is not currently supporting Cisco IOS. See CSCuz49209. There is some mismatch in the cert usage field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2017 20:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599536#M524253</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-06-16T20:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599537#M524254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hsing-Tsu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will it support another ISE ?&lt;/P&gt;&lt;P&gt;I just want to test the SCEP functionality&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to add one ISE server as SCEP server to another ISE but thats failing too.. Not sure if this would work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ultimately we would want to have as SCEP to MDM server. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/108435_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/108436_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2017 19:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599537#M524254</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-06-19T19:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599538#M524256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's tested with ASA only. Here are two LabMinutes video on that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="jive-link-external-small" href="http://www.labminutes.com/sec0213_ise_20_internal_ca_scep_anyconnect_vpn_1" rel="nofollow" style="padding: 0 calc(12px + 0.35ex) 0 0; font-style: inherit; font-family: inherit; color: #007fab;"&gt;How to Configure Cisco ISE 2.0 Internal CA SCEP with AnyConnect VPN (Part 1)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A class="jive-link-external-small" href="http://www.labminutes.com/sec0213_ise_20_internal_ca_scep_anyconnect_vpn_2" rel="nofollow" style="padding: 0 calc(12px + 0.35ex) 0 0; font-style: inherit; font-family: inherit; color: #007fab;"&gt;How to Configure Cisco ISE 2.0 Internal CA SCEP with AnyConnect VPN (Part 2)&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need it supported for external MDM, please bring it up with our PM teams.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2017 19:31:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/3599538#M524256</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-06-19T19:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/4587470#M573923</link>
      <description>&lt;P&gt;Is there still no solution to issue certificates to Cisco devices (routers, switches, wlc) from ISE CA?&lt;/P&gt;&lt;P&gt;From my view It is very disappointing that a Cisco CA (ISE) is not able to issue certificates to their own main product series.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 16:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/4587470#M573923</guid>
      <dc:creator>Andreas Jaeger</dc:creator>
      <dc:date>2022-04-06T16:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/4587687#M573927</link>
      <description>&lt;P&gt;AFAIK this is still not possible. The enhancement 'bug' that was referenced by Hsing below shows a status of Terminated. This is likely because the ISE CA is mainly intended for the BYOD use case (and maybe pxGrid, where needed). It is not intended/supported to be used as an Enterprise CA and that fact is not likely to change.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 22:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/4587687#M573927</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-04-06T22:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as SCEP server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/4590124#M574041</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;I was never asking the ISE to become an Enterprise CA - I was just asking why it does not support Cisco products.&lt;/P&gt;&lt;P&gt;E.g. for RADIUS DTLS with ISE the devices need to have certificates installed, but its own/internal CA is not supporting them.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 12:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-scep-server/m-p/4590124#M574041</guid>
      <dc:creator>Andreas Jaeger</dc:creator>
      <dc:date>2022-04-11T12:07:35Z</dc:date>
    </item>
  </channel>
</rss>

