<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Self Signed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515901#M7614</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACS cert is only needed on the clients if you have the clients trusting the ACS certificate.&lt;/P&gt;&lt;P&gt;For example if you are using PEAP or EAP-TLS and trusting the Server cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have this constraint then you do not need to install the ACS cert on the clients.&lt;/P&gt;&lt;P&gt;You only need to create the ACS cert again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Nov 2010 08:37:36 GMT</pubDate>
    <dc:creator>Tiago Antunes</dc:creator>
    <dc:date>2010-11-16T08:37:36Z</dc:date>
    <item>
      <title>ACS Self Signed</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515899#M7612</link>
      <description>&lt;P&gt;The duration of the certificate of the ACS is one year. This means I have to install the new certificate in workstations, again?? Or only create the new certificate again in the ACS??&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515899#M7612</guid>
      <dc:creator>ricardorojas123</dc:creator>
      <dc:date>2020-02-21T18:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Self Signed</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515900#M7613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes it means you will have to re-install it on the clients. This is why self-signed certificates are not the best solution with regards to admin overhead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best for you would be to setup a CA (openssl, windows server, ...) that issues a certificate to ACS. You could renew the ACS certificate and not change anything to the clients since they trust the CA (and thus all the servers who have a cert of that CA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;Don't forget to rate answers that you find useful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Nov 2010 07:41:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515900#M7613</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2010-11-16T07:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Self Signed</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515901#M7614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACS cert is only needed on the clients if you have the clients trusting the ACS certificate.&lt;/P&gt;&lt;P&gt;For example if you are using PEAP or EAP-TLS and trusting the Server cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have this constraint then you do not need to install the ACS cert on the clients.&lt;/P&gt;&lt;P&gt;You only need to create the ACS cert again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Nov 2010 08:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-self-signed/m-p/1515901#M7614</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-11-16T08:37:36Z</dc:date>
    </item>
  </channel>
</rss>

