<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Certificates in a multi-node deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504349#M537039</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please read &lt;A _jive_internal="true" data-containerid="5301" data-containertype="14" data-objectid="68164" data-objecttype="102" href="https://community.cisco.com/docs/DOC-68164"&gt;How To: Implement ISE Server-Side Certificates&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; if not already done.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The choice is usually governed by the organization policies. Option 1 is more secure. Option 2 is more convenient and works better in some cases. For example, Apple iOS and macOS devices will ask to accept the EAP server certificate if not seen before, when performing an ad-hoc connection with PEAP/MSCHAPv2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Nov 2016 03:29:31 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2016-11-10T03:29:31Z</dc:date>
    <item>
      <title>ISE Certificates in a multi-node deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504348#M537038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the preferred method for admin certificates in a multi-node deployment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Single cert with multiple SAN for each node&lt;/P&gt;&lt;P&gt;2) Shared certificate with multiple SAN among all nodes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I create different cert for each node or just share a single cert among all nodes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2016 02:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504348#M537038</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-11-10T02:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Certificates in a multi-node deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504349#M537039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please read &lt;A _jive_internal="true" data-containerid="5301" data-containertype="14" data-objectid="68164" data-objecttype="102" href="https://community.cisco.com/docs/DOC-68164"&gt;How To: Implement ISE Server-Side Certificates&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; if not already done.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The choice is usually governed by the organization policies. Option 1 is more secure. Option 2 is more convenient and works better in some cases. For example, Apple iOS and macOS devices will ask to accept the EAP server certificate if not seen before, when performing an ad-hoc connection with PEAP/MSCHAPv2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2016 03:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504349#M537039</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-11-10T03:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Certificates in a multi-node deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504350#M537040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Understood.  Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2016 04:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificates-in-a-multi-node-deployment/m-p/3504350#M537040</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-11-10T04:29:15Z</dc:date>
    </item>
  </channel>
</rss>

