<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Import EAP-cert in Cisco ISE 3.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/import-eap-cert-in-cisco-ise-3-3/m-p/5261147#M595013</link>
    <description>&lt;P&gt;That does sound odd. The same EAP System Cert should be importable on multiple nodes, from what I recall. I tend to create a unique cert per node, and ensure there is no wildcard either in the Subject or SAN.&lt;/P&gt;
&lt;P&gt;Usually ISE is quite reliable with regards to cert management. Have you examined the certs with openssl and looked closely at the Serial number and Issuer details? Perhaps there is a clash:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;openssl x509 -in &amp;lt;certname.pem&amp;gt; -text &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 16 Feb 2025 20:35:06 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-02-16T20:35:06Z</dc:date>
    <item>
      <title>Import EAP-cert in Cisco ISE 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/import-eap-cert-in-cisco-ise-3-3/m-p/5261085#M595012</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Getting a weird error in ISE 3.3 when importing the signed cert from our old deployment that we use for EAP. The import worked fine on the first node, but the cert did not show up on the other nodes (signed cert for guest automatically imported to all nodes). When i try to import for node 2, i get the following error:&lt;/P&gt;&lt;P&gt;ISE cannot import a local certificate with the same Issuer CN and serial number as an existing certificate, yet the Issuers of the two certificates differ.&lt;/P&gt;&lt;P&gt;This is exactly the same cert that worked on node 1, so why does it say that the Issuers differ?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Feb 2025 14:00:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/import-eap-cert-in-cisco-ise-3-3/m-p/5261085#M595012</guid>
      <dc:creator>trondaker</dc:creator>
      <dc:date>2025-02-16T14:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Import EAP-cert in Cisco ISE 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/import-eap-cert-in-cisco-ise-3-3/m-p/5261147#M595013</link>
      <description>&lt;P&gt;That does sound odd. The same EAP System Cert should be importable on multiple nodes, from what I recall. I tend to create a unique cert per node, and ensure there is no wildcard either in the Subject or SAN.&lt;/P&gt;
&lt;P&gt;Usually ISE is quite reliable with regards to cert management. Have you examined the certs with openssl and looked closely at the Serial number and Issuer details? Perhaps there is a clash:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;openssl x509 -in &amp;lt;certname.pem&amp;gt; -text &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Feb 2025 20:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/import-eap-cert-in-cisco-ise-3-3/m-p/5261147#M595013</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-02-16T20:35:06Z</dc:date>
    </item>
  </channel>
</rss>

