<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Cert for IOT devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275019#M564845</link>
    <description>&lt;P&gt;This is an existing setup, hence all the relevant NAS-CIsco SW (shared secret) are already in place. Below are the snippets :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- Certificate Template&lt;/P&gt;&lt;P&gt;2- Certificate Profile&lt;/P&gt;&lt;P&gt;3- Authentication Policy (apology, have to amend some of the information due to Prod setup)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During testing, the device does not hit/match the IOT-Cert authentication policy at all, hence it wont be matching the authorization i wanted it to match.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 05:09:05 GMT</pubDate>
    <dc:creator>cxo-179682</dc:creator>
    <dc:date>2021-01-19T05:09:05Z</dc:date>
    <item>
      <title>ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4267616#M564589</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to deploy certificate from ISE to IOT devices for security purposes, but can anyone share which docs can i refer to ?&lt;/P&gt;&lt;P&gt;- create iot device cert from ISE (export to device)&lt;/P&gt;&lt;P&gt;- import ISE cert to the device&lt;/P&gt;&lt;P&gt;- authenticate based on the cert provided (authentication and authorization profiles)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been searching the docs, but been going in circles and couldnt find a complete doc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 08:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4267616#M564589</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-06T08:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4267627#M564590</link>
      <description>&lt;P&gt;For a device to present a certificate to ISE for network authentication it must have and be using an 802.1x supplicant. Do your IoT devices have that? (Most don't)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 08:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4267627#M564590</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-01-06T08:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4268074#M564608</link>
      <description>&lt;P&gt;We are only enabling those that support 802.1x and there are a handful, where we can import the cert &amp;amp; enable dot1x.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm exploring on how to create/generate the cert from ISE and export it to be imported to the said device to be authenticated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 22:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4268074#M564608</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-06T22:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4269828#M564695</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/179682"&gt;@cxo-179682&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use ISE pxGrid as your CA to generate client certificates for your IOT devices. I believe you might need the Plus License installed to see the menu option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The name 'pxGrid' is a bit misleading since in your case it has nothing to do with pxGrid- don't worry - you can generate certs for client devices and in the end it spits out a .zip file that contains all the bits you need. You can even create a cert using a .csr (from your IOT device or OpenSSL) or generate the cert from scratch.&lt;/P&gt;
&lt;P&gt;The cert template is defined in ISE and it will populate the cert attributes in a certain way - but it should be good enough for most purposes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pxgrid.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101307iB3A0DF63368ECB88/image-size/large?v=v2&amp;amp;px=999" role="button" title="pxgrid.PNG" alt="pxgrid.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a client cert you need the EKU (Enhanced Key Usage) to be "Client Certificate' - pxGrid will set the cert to Server and Client - nice!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="arne.PNG" style="width: 600px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101308iBF2B20BFC6B0BF72/image-size/large?v=v2&amp;amp;px=999" role="button" title="arne.PNG" alt="arne.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2021 21:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4269828#M564695</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-10T21:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4271155#M564737</link>
      <description>&lt;P&gt;Thanks for your suggestion for PxGrid, but we do not have the Plus license, hence couldnt use it &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any other suggestion on how i can generate the cert from ISE (to be trusted from the iot device) ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 23:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4271155#M564737</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-12T23:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4271875#M564766</link>
      <description>&lt;P&gt;You could get a 90 day eval of the Plus license (100 endpoints). I am quite certain that once you have created those certificates, they won’t disappear from the system after the 90 days. &amp;nbsp;You might just get a license expiration warning.&amp;nbsp;&lt;BR /&gt;100 Plus licenses should not be too expensive in the long run.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 19:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4271875#M564766</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-13T19:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4272156#M564780</link>
      <description>&lt;P&gt;Thanks again for your prompt assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive managed to get the zip file with all the certs required and imported to the IOT (enabled dot1x).&lt;/P&gt;&lt;P&gt;Created Authentication profile based on the Certificate profile (with relevant Authorization profile to permit the device with specific VLAN)&lt;/P&gt;&lt;P&gt;But, its not hitting/matching the Authentication profile that i wanted for it to check/read the certificate details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apology if this sounds 'stupid', but i couldnt find a proper document for this anywhere..as im getting in circles or im looking it at the wrong place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 07:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4272156#M564780</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-14T07:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4272717#M564787</link>
      <description>&lt;P&gt;I would send some screen shots but I am not near a computer at the moment. The authentication Policy Set needs an allowed Protocols that allows eap-tls and the authentication itself references a certificate profile that specifies if there are parts of the cert that you want to look up (eg the Subject or SAN) etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have a look at the lab minute series video. This is video 1&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.labminutes.com/sec0274_ise_22_wireless_dot1x_eap_tls_peap_1" target="_blank"&gt;https://www.labminutes.com/sec0274_ise_22_wireless_dot1x_eap_tls_peap_1&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 21:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4272717#M564787</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-14T21:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4274935#M564843</link>
      <description>&lt;P&gt;Thanks again for your reply, and i did have a look at the video before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I've done below on the ISE :&lt;/P&gt;&lt;P&gt;- Allowed PEAP &amp;amp; EAP-TLS protocol&lt;/P&gt;&lt;P&gt;- Authentication Profile matching the Certificate profile ive created matching SAN (created via pxGrid)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the client/supplicant :&lt;/P&gt;&lt;P&gt;- enabled 802.1x using certificate (eap-tls)&lt;/P&gt;&lt;P&gt;- imported only machine cert created from pxGrid&amp;nbsp; (there are a lot of other file which i dont think is needed, i maybe wrong again)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But still not 'hitting' the authentication policy ive created &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 01:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4274935#M564843</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-19T01:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4274990#M564844</link>
      <description>&lt;P&gt;post some screen shots of the Policy Set - details of the Authentication, and Authorization please.&lt;/P&gt;
&lt;P&gt;Do you use the NAS (NAD) for anything else in that ISE server? Have you added it to the ISE Devices List and is the Radius shared secret correct? Is the NAS/NAD configured correctly with the ISE IP address and shared secret?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this wired or wireless?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 03:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4274990#M564844</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-19T03:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275019#M564845</link>
      <description>&lt;P&gt;This is an existing setup, hence all the relevant NAS-CIsco SW (shared secret) are already in place. Below are the snippets :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- Certificate Template&lt;/P&gt;&lt;P&gt;2- Certificate Profile&lt;/P&gt;&lt;P&gt;3- Authentication Policy (apology, have to amend some of the information due to Prod setup)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During testing, the device does not hit/match the IOT-Cert authentication policy at all, hence it wont be matching the authorization i wanted it to match.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 05:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275019#M564845</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-19T05:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275538#M564863</link>
      <description>&lt;P&gt;Great screen shots - that helps a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since this is an IOT device, are you 100% sure that the supplicant is correctly configured? In other words, is it sending EAPOL frames towards the switch? You might want to run a tcpdump on the ISE PSN node to confirm that the RADIUS packets do indeed contain EAP payload.&lt;/P&gt;
&lt;P&gt;Here is a handy command to test whether the attached client speaks EAPOL (perhaps hardcode the port to access vlan in order to bring the interface up before running this test)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Arial; font-size: 11.0pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;Test device on access switch port to see whether it has a configured supplicant&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Arial; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Courier New'; font-size: 11.0pt;"&gt;9300# &lt;SPAN style="font-weight: bold;"&gt;term monitor&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Courier New'; font-size: 11.0pt;"&gt;9300# &lt;SPAN style="font-weight: bold;"&gt;dot1x test eapol-capable interface te 1/0/46&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Courier New'; font-size: 11.0pt;"&gt;Mar 27 23:40:29.175: %DOT1X-4-INFO_EAPOL_PING_RESPONSE: Switch 1 R0/0: sessmgrd: The interface Te1/0/46 has an 802.1x capable client with MAC 7872.5d3f.a55a&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you connect the IOT device, what is the end result? Do you see EAP processing on the switch? Do you see the Steps that ISE took to process the Auth request in the Details?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not 100% sure that having two identical Authentication Conditions (Wired 802.1X AND EAP-TLS) will allow you to process the second Rule (e.g. Laptop-Cert) in your case. If laptop or IOT comes along with wired 802.1X and EAP-TLS then Rule 1 is satisfied - and then the cert processing is done and AD lookup etc. - if that fails, then I don't think ISE will continue to Rule 2. I would make each Rule a bit more specific, by including another AND operand such as "CERTIFICATE Issuer = 'blah'" to tell ISE to use that Rule unambiguously.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 20:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275538#M564863</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-19T20:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275571#M564865</link>
      <description>&lt;P&gt;Thanks again for some of the troubleshooting steps, i will proceed to to test the port to confirm the IOT dot1x capabilities (well, the vendor did mentioned he tested with others and it worked, and it's configured for dot1x with eap-tls, which ive checked)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive tried to find a way to 'consolidate' both certificate option for Laptop and IOT, but couldn't, hence i created a 2nd authentication profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure this is being used in other organisation where different certificate will be use or need to check. (this is where i did mentioned that i couldn't find the appropriate documentation)&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 22:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4275571#M564865</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-19T22:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4276264#M564881</link>
      <description>&lt;P&gt;Let us know how you get on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When dealing with multiple EAP-TLS client cert "types" from the same NAS, then you can distinguish them during Authentication using the method I proposed. I have done this in a number of projects. You have access to the CERTIFICATE attributes during authentication, and therefore you can point ISE in the right direction regarding WHICH certificate attribute you are interested in for authentication (certificate profile selection).&lt;/P&gt;
&lt;P&gt;The Policy Set will not continue processing if you have matched a Rule, but then proceed to fail during Authentication (e.g. IOT client cert&amp;nbsp; comes along, and you perform auth using the Employee client profile ... Authentication should(will) fail - and then the Access-Reject is sent to the NAS - end of story). You don't get to "fail through" to the next rule.&amp;nbsp; &amp;nbsp;There is an option in Authentication called "If Auth Fail 'Continue'" - but Continue in this case means, continue to Authorization (and bypass Authentication).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 22:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4276264#M564881</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-20T22:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4277181#M564907</link>
      <description>&lt;P&gt;I think i managed to get it worked after few tries, as im not sure is the IOT device or ISE configuration issue :&lt;/P&gt;&lt;P&gt;1- No separate certificate profile needed (if there's one in place already)&lt;/P&gt;&lt;P&gt;2- Create cert via pxgrid (as suggested by you)&lt;/P&gt;&lt;P&gt;3- Imported Root and Machine cert to the IOT device (enabled 802.1x)&lt;/P&gt;&lt;P&gt;4- Create an authorization profile matching the cert details and assign appropriate access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tested few devices and it worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; but I've been advised to use ISE PKI certificate instead of pxGrid.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 23:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4277181#M564907</guid>
      <dc:creator>cxo-179682</dc:creator>
      <dc:date>2021-01-21T23:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4277221#M564909</link>
      <description>&lt;P&gt;congrats. If you have found any of our interactions useful then you can tick the "helpful" icon and then eventually click the button "Accept as Solution" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 00:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4277221#M564909</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-22T00:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert for IOT devices</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4927690#M584196</link>
      <description>&lt;P&gt;To deploy certificates from Cisco Identity Services Engine (ISE) to IoT devices for enhanced security, you can follow these steps:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Generate an IoT device certificate on ISE: Access ISE's Certificate Authority (CA) to create a certificate for the IoT device. Ensure it's configured with the necessary details and exportable.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Import ISE certificate to the device: Install the ISE CA certificate on the IoT device's certificate store, allowing the device to trust certificates issued by ISE.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Configure authentication and authorization profiles: Set up authentication policies in ISE, associating them with the IoT device certificate. Create authorization profiles that define access rights based on the device's certificate attributes.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Test authentication: Verify the setup by having the IoT device attempt to connect, utilizing its certificate for authentication. Ensure the ISE policies correctly grant or deny access based on the certificate attributes.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;While Cisco provides documentation, consider consulting Cisco's official documentation and forums for more detailed instructions tailored to your specific ISE and device configurations.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 08:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-for-iot-devices/m-p/4927690#M584196</guid>
      <dc:creator>shreyiot</dc:creator>
      <dc:date>2023-09-22T08:55:59Z</dc:date>
    </item>
  </channel>
</rss>

