<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - Two end user certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529861#M535662</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes that is exactly what I'm trying to do Jason. &lt;/P&gt;&lt;P&gt;I think you are right - unless someone out there has had experience of getting this working?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Jun 2017 17:49:27 GMT</pubDate>
    <dc:creator>jphilp</dc:creator>
    <dc:date>2017-06-06T17:49:27Z</dc:date>
    <item>
      <title>ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529859#M535654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if it is possible to have two end user certificates on an ISE in order to carry out EAP-TLS to devices from two different CA's - i.e. WLAN 1 uses certificates from one CA and WLAN 2 using certificates from a totally separate CA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try and bind the CSR's from the second CA, the ISE tells me that I can only have one system cert used for EAP and the existing one will be replaced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 17:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529859#M535654</guid>
      <dc:creator>jphilp</dc:creator>
      <dc:date>2017-06-06T17:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529860#M535659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You’re asking if ISE can present a different server cert to the clients authentication with 802.1x depending on the SSID they connec to?  I don’t think that’s possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 17:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529860#M535659</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-06-06T17:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529861#M535662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes that is exactly what I'm trying to do Jason. &lt;/P&gt;&lt;P&gt;I think you are right - unless someone out there has had experience of getting this working?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 17:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529861#M535662</guid>
      <dc:creator>jphilp</dc:creator>
      <dc:date>2017-06-06T17:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529862#M535664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please review &lt;A _jive_internal="true" data-containerid="5301" data-containertype="14" data-objectid="68164" data-objecttype="102" href="https://community.cisco.com/docs/DOC-68164" style="padding: 1px 0 1px 17px; font-weight: normal; font-style: normal; font-size: 12px; font-family: arial; color: #0a63a7; text-decoration: underline; text-align: left; text-indent: 0px; background-position: no-repeat no-repeat;"&gt;How To: Implement ISE Server-Side Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If simply needing ISE to auth endpoints signed by multiple certificate authority chains, then we need only import the individual certificates from the various chains to the trusted certificate store and marked as trusted for client authentications. You are correct that ISE supports only one single system certificate per ISE node used for the EAP server. There is an enhancement request to what you are asking but that is only needed for the use cases where the clients not wanting to trust EAP servers signed by other CAs so that is a corner case. If that is something you would us to implement, please ask your account team to discuss it with our product management team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 20:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529862#M535664</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-06-06T20:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529863#M535668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd like to see this too and technically there is no reason why it can't be done. You can do it with Portals (multiple certificates), be good for EAP too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DJ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jun 2017 06:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529863#M535668</guid>
      <dc:creator>dazza_johnson</dc:creator>
      <dc:date>2017-06-07T06:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529864#M535670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you know any EAP server able to use two certificates, please let us know.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;It's not as easy as ISE end-user facing portals, such as ISE guest portals, because the user browsers can go to different combination of FQDNs and ports and ISE is currently able to provide a different certificate for each port, as this is a fairly standard way for secure web sites. Even for web portals, ISE is not supporting server name indication (SNI) so we have to use different ports. There is nothing like such for EAP protocols, AFAIK.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In fact, you could in theory to simulate the same by directing your network devices to different PSNs and each uses a system certificate, either signed by CA-1 or by CA-2.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jun 2017 22:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529864#M535670</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-06-07T22:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529865#M535671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can we support different EAP certificates per interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jun 2017 23:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529865#M535671</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-06-08T23:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529866#M535672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. One EAP certificate per ISE PSN. If you need two, then use two different PSNs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 00:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529866#M535672</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-06-09T00:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529867#M535673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. I tried this on our PSN and it took the EAP role off the existing certificate just leaving EAP assigned to the new certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 08:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529867#M535673</guid>
      <dc:creator>jphilp</dc:creator>
      <dc:date>2017-06-09T08:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Two end user certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529868#M535674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;So if I have an ISE cluster with two distinct organistions where endpoints don't trust a common CA, I can partition my PSNs such that some are used for Org 1 with a server cert from CA1 and the other PSNs used for Org 2 with server cert from CA2&lt;STRONG&gt;?&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;NADs from Org 1 are configured to use PSNs for Org 1, and similar arrangement for other org.&lt;/P&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Limitation that any endpoints from Org 1 that connect to a NAD in Org 2 would still fail the certificate trust.&lt;/P&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Verdana; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Assumes that admin and intra-cluster traffic uses a common cert from CA1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 16:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-two-end-user-certificates/m-p/3529868#M535674</guid>
      <dc:creator>mikoconn</dc:creator>
      <dc:date>2018-04-19T16:54:22Z</dc:date>
    </item>
  </channel>
</rss>

