<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE deployment with self signed certs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-self-signed-certs/m-p/5209845#M592507</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/309358"&gt;@REJR77&lt;/a&gt; the certificates need to be trusted, so yes if using the self signed certificate import the admin certificate to the other node.&lt;/P&gt;
&lt;P&gt;If the customer has no PKI environment, use a publically signed certificate for the EAP certificate and PEAP/MSCHAPv2. The clients should already have the public CA certificate in the local computer store, so would trust that certificate. Using PEAP/MSCHAPv2 is no longer recommended though, as this is blocked by Windows credentials guard. The recommendation is to use user/machine certificates for authentication, which you will need a PKI environment.&lt;/P&gt;
&lt;P&gt;FYI, ISE does have an internal CA builtin, but that is recommended for BYOD environments.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2024 20:11:03 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-10-16T20:11:03Z</dc:date>
    <item>
      <title>ISE deployment with self signed certs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-self-signed-certs/m-p/5209842#M592506</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Usually I use certificate signed by Internal CA, but my customer does not have an PKI and we need to deploy an ISE deployment with self signed.&lt;/P&gt;
&lt;P&gt;Do we need to add each ISE admin cert&amp;nbsp; in trusted CA list on the other node ? (PAN Admin certs on secondary Pan and vice versa?)&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 20:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-self-signed-certs/m-p/5209842#M592506</guid>
      <dc:creator>REJR77</dc:creator>
      <dc:date>2024-10-16T20:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE deployment with self signed certs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-with-self-signed-certs/m-p/5209845#M592507</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/309358"&gt;@REJR77&lt;/a&gt; the certificates need to be trusted, so yes if using the self signed certificate import the admin certificate to the other node.&lt;/P&gt;
&lt;P&gt;If the customer has no PKI environment, use a publically signed certificate for the EAP certificate and PEAP/MSCHAPv2. The clients should already have the public CA certificate in the local computer store, so would trust that certificate. Using PEAP/MSCHAPv2 is no longer recommended though, as this is blocked by Windows credentials guard. The recommendation is to use user/machine certificates for authentication, which you will need a PKI environment.&lt;/P&gt;
&lt;P&gt;FYI, ISE does have an internal CA builtin, but that is recommended for BYOD environments.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 20:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-with-self-signed-certs/m-p/5209845#M592507</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-16T20:11:03Z</dc:date>
    </item>
  </channel>
</rss>

