<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authenticating a device with certificates using ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticating-a-device-with-certificates-using-ise/m-p/4396997#M567085</link>
    <description>&lt;P&gt;Few items for consideration: Is this possibly something for another customer? If so, any chance you could enroll them with your internal PKI &amp;amp; use that cert to onboard the non-domain clients to your network? Who will manage the configuration of the supplicant (you/external domain)?&amp;nbsp; Also, what type of supplicant will be in use? You will need to consider how to do certificate matching if the client will have multiple identity certs from different domains.&amp;nbsp; If the clients have an identity cert and you trust the chain, have you considered simply adding the external chain into your ISE trust store to support onboarding via their own PKI certs?&lt;/P&gt;</description>
    <pubDate>Mon, 03 May 2021 13:14:08 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2021-05-03T13:14:08Z</dc:date>
    <item>
      <title>Authenticating a device with certificates using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-a-device-with-certificates-using-ise/m-p/4396926#M567083</link>
      <description>&lt;P&gt;I want to authenticate a device which is not on the domain (not connected to AD), using certificate. Is it possible to do certificate based authentication using the ISE default certificate? by generating CSR. etc.&lt;/P&gt;&lt;P&gt;The device doesn't allow username/password authentication, can I use the certificates only? Like when you configure SSH with pub-key.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 10:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-a-device-with-certificates-using-ise/m-p/4396926#M567083</guid>
      <dc:creator>SMD28316</dc:creator>
      <dc:date>2021-05-03T10:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating a device with certificates using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-a-device-with-certificates-using-ise/m-p/4396997#M567085</link>
      <description>&lt;P&gt;Few items for consideration: Is this possibly something for another customer? If so, any chance you could enroll them with your internal PKI &amp;amp; use that cert to onboard the non-domain clients to your network? Who will manage the configuration of the supplicant (you/external domain)?&amp;nbsp; Also, what type of supplicant will be in use? You will need to consider how to do certificate matching if the client will have multiple identity certs from different domains.&amp;nbsp; If the clients have an identity cert and you trust the chain, have you considered simply adding the external chain into your ISE trust store to support onboarding via their own PKI certs?&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 13:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-a-device-with-certificates-using-ise/m-p/4396997#M567085</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-05-03T13:14:08Z</dc:date>
    </item>
  </channel>
</rss>

