<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I have not yet created the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512028#M72978</link>
    <description>&lt;P&gt;I have not yet created the CSR, and thank you for the instructions. &amp;nbsp;My confusion is this:&lt;/P&gt;&lt;P&gt;I have the actual wildcard cert (*.domain.com cert), along with the CA bundle. &amp;nbsp;I have imported the CA bundle already, but is there anything i should be doing with the *.domain.com cert?&lt;/P&gt;&lt;P&gt;Does it need to be imported, or is it useless? &amp;nbsp;My understanding of a wildcard cert is that the single cert can be installed on whatever you'd like to use it on... or do you still need to go through the CSR process for each application on which you'd like to use it?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Sep 2014 17:02:32 GMT</pubDate>
    <dc:creator>MMstre</dc:creator>
    <dc:date>2014-09-19T17:02:32Z</dc:date>
    <item>
      <title>Installing wildcard cert on ISE for HTTP/EAP</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512026#M72976</link>
      <description>&lt;P&gt;I need to install a wildcard cert on ISE, but have no experience with wildcards. &amp;nbsp;I have the *.domain certificate, but i am not sure of the process, and the Cisco docs add to the confusion. &amp;nbsp;Am i supposed to generate a new CSR to give to the CA, do i simply install the *.domain cert? &amp;nbsp;I have read the install guide and it of course makes the assumption that you know what you're talking about, and when it comes to installing wildcards, i don't know...&lt;/P&gt;&lt;P&gt;Any assistance would be greatly appreciated&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512026#M72976</guid>
      <dc:creator>MMstre</dc:creator>
      <dc:date>2019-03-13T00:43:16Z</dc:date>
    </item>
    <item>
      <title>Hi,In order to create CSR</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512027#M72977</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In order to create CSR file from the ISE using a wildcard certificate, you can do the following:&lt;/P&gt;&lt;P&gt;From the CSR page, enter the CN=*.yourdomain.com&lt;/P&gt;&lt;P&gt;and If you have a specific DNS entry for your ISE like ise1.yourdomain.com under the SAN fields.&lt;/P&gt;&lt;P&gt;Also, you need to check the box of "Allow Wildcard Certificate".&lt;/P&gt;&lt;P&gt;After that, you can generate and export the CSR and submit it to your CA to get the ID certificate (which you will bind it with the CSR).&lt;/P&gt;&lt;P&gt;Also, you need the CA certificate itself to be added on the ISE certificate store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Ahmad.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 16:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512027#M72977</guid>
      <dc:creator>Ahmad Murad</dc:creator>
      <dc:date>2014-09-19T16:26:55Z</dc:date>
    </item>
    <item>
      <title>I have not yet created the</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512028#M72978</link>
      <description>&lt;P&gt;I have not yet created the CSR, and thank you for the instructions. &amp;nbsp;My confusion is this:&lt;/P&gt;&lt;P&gt;I have the actual wildcard cert (*.domain.com cert), along with the CA bundle. &amp;nbsp;I have imported the CA bundle already, but is there anything i should be doing with the *.domain.com cert?&lt;/P&gt;&lt;P&gt;Does it need to be imported, or is it useless? &amp;nbsp;My understanding of a wildcard cert is that the single cert can be installed on whatever you'd like to use it on... or do you still need to go through the CSR process for each application on which you'd like to use it?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 17:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512028#M72978</guid>
      <dc:creator>MMstre</dc:creator>
      <dc:date>2014-09-19T17:02:32Z</dc:date>
    </item>
    <item>
      <title>Unfortunately, you need first</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512029#M72979</link>
      <description>&lt;P&gt;Unfortunately, you need first to create a CSR with wildcard filed either on the CN or DNS fields, and then you need to sign this CSR from the CA using the exact same values and bind it again to the CSR on the ISE configuration.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Sep 2014 07:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512029#M72979</guid>
      <dc:creator>Ahmad Murad</dc:creator>
      <dc:date>2014-09-20T07:40:34Z</dc:date>
    </item>
    <item>
      <title>If you are already in the</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512030#M72980</link>
      <description>&lt;P&gt;If you are already in the possession of the wildcard cert and the private key, then you don't need CSR. You can simply import the certificate in ISE:&lt;/P&gt;&lt;P&gt;1. Go to Administration &amp;gt; Certificates &amp;gt; Local Certificates &amp;gt; &amp;nbsp;Add &amp;gt; Import Server Certificate&lt;/P&gt;&lt;P&gt;2. Use the "browse" buttons to point to the certificate file and private key&lt;/P&gt;&lt;P&gt;3. Check "Allow Wildcard Certificates"&lt;/P&gt;&lt;P&gt;4. Select the protocol that you want to use it for (EAP or HTTPS or both)&lt;/P&gt;&lt;P&gt;5. Hit submit&lt;/P&gt;&lt;P&gt;6. Go to Certificates Store&lt;/P&gt;&lt;P&gt;7. Import the root CA certificate and Intermediate CA certificate(s) (If any)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Sep 2014 17:48:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512030#M72980</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-09-21T17:48:40Z</dc:date>
    </item>
    <item>
      <title>A word of caution. If you are</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512031#M72981</link>
      <description>&lt;P&gt;A word of caution. If you are planning to use this cert for 802.1x in BYOD environments you should look into using a SAN cert instead. with all your PSNs in it, wildcard certs are not good for windows machines in e peap/byod scenario, and iOS also has issues with certain wildcard certs.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 03:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/2512031#M72981</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2014-09-29T03:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: A word of caution. If you are</title>
      <link>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/4936243#M584471</link>
      <description>&lt;P&gt;Hi Jan sorry for this question but for my understand:&lt;/P&gt;
&lt;P&gt;I have two ISE node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) PAN PSN MnT name ise1.ise.labdomain.com&lt;/P&gt;
&lt;P&gt;2)&amp;nbsp;PAN PSN MnT name ise2.ise.labdomain.com&lt;/P&gt;
&lt;P&gt;In the CSR what name i need to PUT in the CN and in the SAN ?&lt;/P&gt;
&lt;P&gt;In the SAN i put *.ise.labdomain.com but you mention alse PSN ... Can you explain me this behaviour please ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 10:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/installing-wildcard-cert-on-ise-for-http-eap/m-p/4936243#M584471</guid>
      <dc:creator>m.cucchi</dc:creator>
      <dc:date>2023-10-08T10:41:31Z</dc:date>
    </item>
  </channel>
</rss>

