<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Generating CSR Error on ISE for System Certificate used for EAP Au in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4934464#M584422</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hi Greg&lt;BR /&gt;How to renew certificate with the same CN,OU,O,....?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2023 04:34:46 GMT</pubDate>
    <dc:creator>jewfcb001</dc:creator>
    <dc:date>2023-10-05T04:34:46Z</dc:date>
    <item>
      <title>Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066008#M559616</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quite new to the whole experience of ISE and Certificate based authentication on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to generate a CSR for a System EAP authentication certificate that expires on 7th May for us. While trying to generate CSR however, I get below error message and the CSR does not get generated. How can I get beyond this? I am not sure if I should change any of the details from existing certificate.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE CSR Error.PNG" style="width: 674px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/71701i4F6603B34A1C881C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE CSR Error.PNG" alt="ISE CSR Error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 03:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066008#M559616</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2020-04-15T03:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066017#M559617</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;The csr your generating must'nt have same values in all fields as the on existing today already in use. Have you validated that you're filling in the same values on all fields?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit:typo error&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 03:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066017#M559617</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-04-15T03:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066020#M559619</link>
      <description>&lt;P&gt;ISE will not allow creating a CSR or binding a certificate that has the same Subject as another certificate. A common approach is to modify one of the certificate fields so that there is no matching Subject value.&lt;/P&gt;
&lt;P&gt;I typically use the OU field in the certificate to indicate the Usage (Admin, EAP, etc) of the certificate to avoid duplicate Subject value issues. When renewing a certificate, I often just modify the same OU field slightly (like adding the Month/Year) to produce a unique Subject value.&lt;/P&gt;
&lt;P&gt;I haven't seen anyone using the OU attribute as a matching condition in policies, so it is often easy to change.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 03:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066020#M559619</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-15T03:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066029#M559620</link>
      <description>&lt;P&gt;Thank you for the inputs. So I can add to OU field and make it different and ensure it isn't use in any policy matching, and it should be fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brings me to another important issue I am facing with CSR though - I am doing it for two nodes at the same time - how do I fill up the CN field under Subject in that case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 04:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066029#M559620</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2020-04-15T04:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066036#M559621</link>
      <description>&lt;P&gt;There are two typical approaches... wildcard certificates or Subject Alternative Name (SAN).&lt;/P&gt;
&lt;P&gt;Some clients might not support wildcard certs for EAP authentication so, when I've had a similar customer wanting to use a single EAP cert for multiple PSNs, I've used the SAN option.&lt;/P&gt;
&lt;P&gt;You would create the CSR (on PSN1) such that the CN = PSN1 FQDN and the SAN field has both the PSN1 and PSN2 FQDNs (in that order).&lt;/P&gt;
&lt;P&gt;You would then bind the cert to the CSR on PSN1, export the certificate with the key, then import the cert into PSN2.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 04:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066036#M559621</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-15T04:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066037#M559622</link>
      <description>Not sure i get your question correctly for cn.&lt;BR /&gt;By default, it's filled in with the keyword fqdn and ise will use the fqdn of each server automatically for each csr you generate (1 at a time).&lt;BR /&gt;&lt;BR /&gt;If you want to have only 1 cert, you can do 1 csr, export it with its private key and import it on all other nodes.</description>
      <pubDate>Wed, 15 Apr 2020 04:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066037#M559622</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-04-15T04:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066056#M559623</link>
      <description>&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So sounds like there is two ways, although I find it much simpler if I let it use the FQDN under CN field, if it works. Currently CN field has by default $FQDN$ so that should work so long as I update one of the other fields, say OU to differentiate the certs from the existing ones and then it should all fall in place.&lt;/P&gt;&lt;P&gt;So I would generate CSR with those two fields as below for eg.:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE CSR CN and OU field.PNG" style="width: 598px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/71708i5BE05BF73F847000/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE CSR CN and OU field.PNG" alt="ISE CSR CN and OU field.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 05:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066056#M559623</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2020-04-15T05:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066799#M559661</link>
      <description>Yes. If you want to have 1 certificate for both, you can add dns names into SAN. Also you can change the fqdn variable by something like eap.company.com to have something common. /however, you can move with 2 certificates as you said,</description>
      <pubDate>Wed, 15 Apr 2020 22:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4066799#M559661</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-04-15T22:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4071069#M559819</link>
      <description>One final query on this one guys - How can I restore previous certificate, if for any reason the new certificate does not work? Would it just be a matter of ticking/unticking the EAP authentication check box on the certificates? I note that currently I am not able to untick the EAP authentication option on the ceritificate in use. Also, should I be exporting the existing certificate with its private key as backup before changing over to new certificate? It might all turn out to be pretty straightforward, but I haven't been across such a change before, so trying to ensure all backup measures are in place. This one being EAP authentication certifciate, would affect all wired users authentication.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;</description>
      <pubDate>Wed, 22 Apr 2020 01:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4071069#M559819</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2020-04-22T01:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4071086#M559821</link>
      <description>&lt;P&gt;ISE requires that the EAP function (usage) is assigned to a certificate (and only one) so you cannot simply remove EAP from the existing certificate. You would have to install a new certificate with the EAP usage and ISE will move the EAP usage from the old to the new cert.&lt;/P&gt;
&lt;P&gt;As long as the new certificate has a different Subject than the old cert, the old cert should remain on ISE until you delete it. In that case, if the new cert does not work, you should be able to move the EAP usage back to the old cert.&lt;/P&gt;
&lt;P&gt;Best practice, however, is to export all identity certificates with their keys and copy them to a safe location that has strong security controls. That way, you can simply re-import them in the event of an unrecoverable node failure and not have to create new CSRs, trust chains, etc.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 02:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4071086#M559821</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-22T02:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Au</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4934464#M584422</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hi Greg&lt;BR /&gt;How to renew certificate with the same CN,OU,O,....?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 04:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4934464#M584422</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-10-05T04:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Au</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4935113#M584440</link>
      <description>&lt;P&gt;If you install a certificate with the same Subject as an existing certificate, ISE will throw a warning and the existing certificate will be deleted and replaced with the new one. If you run into issues with the new certificate, you will need to re-import the old certificate with the private key, which will again replace the new one.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 22:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4935113#M584440</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-10-05T22:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Au</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4935163#M584445</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;You mean .&amp;nbsp;&lt;BR /&gt;1. Delete the exsiting certificate and change role (Admin / EAP Authen / Portal) to new Cert&amp;nbsp;&lt;BR /&gt;2. CSR with same attribute and sign then install to ISE change role to (Admin/EAP Authen/Portal)&lt;BR /&gt;Am I correct?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 01:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4935163#M584445</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2023-10-06T01:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Generating CSR Error on ISE for System Certificate used for EAP Au</title>
      <link>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4935209#M584447</link>
      <description>&lt;P&gt;You can do it that way, but it will cause a restart of the ISE services every time you move the Admin role to another certificate.&lt;/P&gt;
&lt;P&gt;You can create a CSR with the same subject. ISE will throw a warning, but the old certificate won't be deleted until the new signed certificate is bound to the CSR.&lt;/P&gt;
&lt;P&gt;My preference, however, is to make a minor change in the subject (like the OU) so you can install the new certificate without warning or replacement. You can then move the relevant role(s) to the new certificate. If there is any issue with the new certificate, you can easily move the role(s) back to the old certificate without having to re-import it with the private key (which would then delete the new certificate)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 04:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/generating-csr-error-on-ise-for-system-certificate-used-for-eap/m-p/4935209#M584447</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-10-06T04:49:39Z</dc:date>
    </item>
  </channel>
</rss>

