<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Cert Question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070914#M588784</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; it can be anything, generally put a useful name related to its purpose.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 14:23:44 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-04-16T14:23:44Z</dc:date>
    <item>
      <title>ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069571#M588735</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Do I need to generate a CSR for a cert on ISE its a *cert or can I just add the cert to the ISE Nodes for Portal use.??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 13:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069571#M588735</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-15T13:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069578#M588736</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; no you do not need to generate the CSR on ISE itself. It can be generated by other means, but when you import the signed certificate into ISE you will need to import the private key.&lt;/P&gt;
&lt;DIV id="tinyMceEditor_69087e38c3a17eRobIngram_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 781px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215798i21AFC5FCC1B09F53/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This is quite common if you use a wildcard/multi-domain certificate.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 14:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069578#M588736</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-15T14:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069637#M588737</link>
      <description>&lt;P&gt;Yes you need.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check this&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 14:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069637#M588737</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-15T14:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069667#M588739</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for that, do the Certs have to be apache ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 14:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069667#M588739</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-15T14:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069699#M588740</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; I assume you are referring to when processing the CSR via a public provider? Yes, I imagine apache would work.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 14:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069699#M588740</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-15T14:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069756#M588744</link>
      <description>&lt;P&gt;You can use "Other" if that is an option, if not any web server template should work.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 16:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5069756#M588744</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-15T16:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070765#M588774</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Yes I was refering to that process, do you know which other formats would work as well.??&lt;BR /&gt;also if I select generate CSR do I choose portal now or do the uasgae later,? and also see image do I select all the ised nodes for the CSR ?? and check the wildcard box ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="benolyndav_0-1713271062320.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215901iAAA7262916CE1B82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="benolyndav_0-1713271062320.png" alt="benolyndav_0-1713271062320.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070765#M588774</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-16T12:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070783#M588775</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; that screenshot is if you create the CSR on ISE, I thought you weren't going to do that?&lt;/P&gt;
&lt;P&gt;If you do use ISE to generate the CSR when you select "allow wildcard certificate" all the nodes disappear (meaning you cannot select them) and you define the certificate options (CN, OU etc). One CSR is created, get it signed and then import to all the other ISE nodes and assign the usage as Portal.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070783#M588775</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-16T12:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070800#M588778</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hi great I never noticed that, and yes I might have to generate from ISE afterall,&amp;nbsp; So would you suggest leaving as multi use until I have the signed Cert back then when importing to each node there I select portal usage ??&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="benolyndav_0-1713272877245.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215903iF28AD36C1080C319/image-size/medium?v=v2&amp;amp;px=400" role="button" title="benolyndav_0-1713272877245.png" alt="benolyndav_0-1713272877245.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070800#M588778</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-16T13:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070805#M588779</link>
      <description>&lt;P&gt;If the cert will be used on the portal then you should select the portal usage and associate the CSR to the portal group that will use the cert, however, even if you select multi-use and then you associate it to the portal usage it would work anyway, but there is no point to do it that way.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070805#M588779</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-16T13:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070818#M588781</link>
      <description>&lt;P&gt;Dont waste your time' do csr for portal cert.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070818#M588781</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-16T13:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070838#M588782</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; If the certificate is just used for Portal select portal.&lt;/P&gt;
&lt;P&gt;Selecting the usage of a certificate is just a tick box, you can change the usage of other certificates anytime. &lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:32:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070838#M588782</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-16T13:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070909#M588783</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can the friendly name be anything, its appending the ISE node name on the freindly name, and I need to add to other nodes, does this matter.?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 14:20:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070909#M588783</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-16T14:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070914#M588784</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; it can be anything, generally put a useful name related to its purpose.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 14:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5070914#M588784</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-16T14:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071547#M588797</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So got the CSR binded and looks ok, another question I'm assuming I need the new root cert in trusted certs in ISE, what should I select regarding trusted for , and also does addding a cert to trusted certs trigger a services restart.??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071547#M588797</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-17T09:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071554#M588798</link>
      <description>&lt;P&gt;Importing the root certificate (and the intermediate cert if used) into the trusted certificates store in ISE does not trigger any applications reload and you need to select the "Trust for client authentication and Syslog" option to allow ISE to accept the negotiation with the clients presenting a certificate issued by that root or intermediate CA.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071554#M588798</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-17T09:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071555#M588799</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;yes you need to import the root and intermediate root certificate, trusted for authentication.&lt;/P&gt;
&lt;P&gt;No services won't restart for the portal certificate only admin cert.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:23:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071555#M588799</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-17T09:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071568#M588800</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Which one please there is multiple authentication options&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="benolyndav_0-1713346889635.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215984iA3A09FF9F4239475/image-size/medium?v=v2&amp;amp;px=400" role="button" title="benolyndav_0-1713346889635.png" alt="benolyndav_0-1713346889635.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071568#M588800</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-04-17T09:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Cert Question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071604#M588801</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp; "trusted for authentication within ISE" and the sub options.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 10:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert-question/m-p/5071604#M588801</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-17T10:06:07Z</dc:date>
    </item>
  </channel>
</rss>

