<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can ISE 3.2 be configured as Cert Auth? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215051#M592673</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1536919"&gt;@oscardenizjensen&lt;/a&gt; ISE does have a built-in CA, generally it is only used for BYOD scenarios to distribute client certificates and signing pxGrid certificates. So you can use the ISE CA to distribute a certificate to a client.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-30/217161-ca-service-and-est-service-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-30/217161-ca-service-and-est-service-on-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-640661554" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-640661554&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In a normal ISE deployment, organisations would use an Enterprise CA (such as Microsoft CA) to distribute and manage certificates.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2024 10:36:28 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-10-25T10:36:28Z</dc:date>
    <item>
      <title>Can ISE 3.2 be configured as Cert Auth?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215046#M592672</link>
      <description>&lt;P&gt;Hej&lt;BR /&gt;I have a lab environment, and currently don't have a CA in the lab&lt;BR /&gt;&lt;BR /&gt;I was wondering whether I could configure ISE itself as a CA to issue client certs for lab testing purposes. Do I need an external CA regardless?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 10:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215046#M592672</guid>
      <dc:creator>oscardenizjensen</dc:creator>
      <dc:date>2024-10-25T10:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE 3.2 be configured as Cert Auth?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215051#M592673</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1536919"&gt;@oscardenizjensen&lt;/a&gt; ISE does have a built-in CA, generally it is only used for BYOD scenarios to distribute client certificates and signing pxGrid certificates. So you can use the ISE CA to distribute a certificate to a client.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-30/217161-ca-service-and-est-service-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-30/217161-ca-service-and-est-service-on-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-640661554" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-640661554&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In a normal ISE deployment, organisations would use an Enterprise CA (such as Microsoft CA) to distribute and manage certificates.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 10:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215051#M592673</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-25T10:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE 3.2 be configured as Cert Auth?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215056#M592674</link>
      <description>&lt;P&gt;I wanted it mostly for anyconnect testing on windows machines in lab with a Cert&amp;amp;AAA login&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 10:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215056#M592674</guid>
      <dc:creator>oscardenizjensen</dc:creator>
      <dc:date>2024-10-25T10:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE 3.2 be configured as Cert Auth?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215059#M592675</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1536919"&gt;@oscardenizjensen&lt;/a&gt; so use the ISE CA to generate the certificate and import that to the client and as long as ISE and the client mutually trust their certificates it should work.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provisioning-Portal.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provisioning-Portal.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 10:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215059#M592675</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-25T10:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can ISE 3.2 be configured as Cert Auth?</title>
      <link>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215899#M592702</link>
      <description>&lt;P&gt;As an easy alternative to make some certs, take a look at the &lt;A href="https://hohnstaedt.de/xca/" target="_self"&gt;excellent XCA tool&lt;/A&gt; - there are very good guided steps on creating a CA, and then makig client certs - it's open source and well maintained. GUI versions for all desktop OS's.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 23:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-ise-3-2-be-configured-as-cert-auth/m-p/5215899#M592702</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-10-27T23:17:36Z</dc:date>
    </item>
  </channel>
</rss>

