<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a limit to how many CA Server Cert's can be used? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423291#M536967</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no validated limit to the number of CA. As long as the CA root cert and/or intermediate certificate in the Trusted certificate section for the right set of services such as EAP, Admin etc, the client certificate will be validated. The AD domains ISE support can be in a single or multiple forests. &lt;/P&gt;&lt;P&gt;For ISE performance metrics, please see &lt;A href="https://community.cisco.com/docs/DOC-68347"&gt;ISE Performance &amp;amp;amp; Scale&lt;/A&gt; community page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Nov 2016 17:59:05 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2016-11-17T17:59:05Z</dc:date>
    <item>
      <title>Is there a limit to how many CA Server Cert's can be used?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423290#M536966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;50 different AD domains.&lt;/P&gt;&lt;P&gt; We know that ISE can support up to 50 AD domains however this is not the issue we are concerned about.&lt;/P&gt;&lt;P&gt;What concerns us is that each one of those 50 domains has a separate Microsoft CA / PKI environment and the client wants to perform certificate based authentication for all endpoints from all of the 50 AD domains.&lt;/P&gt;&lt;P&gt;I've skimmed through the 'Managing Certificates' chapter of: &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21.pdf" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There does not seem to be any indication as to a limit of certificates, so then does the limit fall in the number of AD Forest that are supported (50)? You just need to pull the cert onto ISE from each CA in each forest?&lt;/P&gt;&lt;P&gt;Let's make the assumption whether domains or forest that there is NO two way trust.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2016 17:52:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423290#M536966</guid>
      <dc:creator>algoldst</dc:creator>
      <dc:date>2016-11-16T17:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a limit to how many CA Server Cert's can be used?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423291#M536967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no validated limit to the number of CA. As long as the CA root cert and/or intermediate certificate in the Trusted certificate section for the right set of services such as EAP, Admin etc, the client certificate will be validated. The AD domains ISE support can be in a single or multiple forests. &lt;/P&gt;&lt;P&gt;For ISE performance metrics, please see &lt;A href="https://community.cisco.com/docs/DOC-68347"&gt;ISE Performance &amp;amp;amp; Scale&lt;/A&gt; community page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2016 17:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423291#M536967</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2016-11-17T17:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a limit to how many CA Server Cert's can be used?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423292#M536969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If asking the max # of Trusted Certs, here are the numbers:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maximum # User Certificates&amp;nbsp;&amp;nbsp;&amp;nbsp; 1M&lt;/P&gt;&lt;P&gt;Maximum # Server Certificates&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&lt;/P&gt;&lt;P&gt;Maximum # Trusted Certificates&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2016 18:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-limit-to-how-many-ca-server-cert-s-can-be-used/m-p/3423292#M536969</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2016-11-17T18:50:46Z</dc:date>
    </item>
  </channel>
</rss>

