<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Jatin. Thanks for the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462384#M86447</link>
    <description>&lt;P&gt;Hello Jatin. Thanks for the response. It was very helpful. You mentioned that the CSR cannot be generated from the ISE GUI. I believe that in 1.2 you can add the SAN DNS to the CSR in the GUI.&lt;/P&gt;&lt;P&gt;Im not sure if that document is referring to an older version? Can you confirm this? Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Apr 2014 14:45:00 GMT</pubDate>
    <dc:creator>west33637</dc:creator>
    <dc:date>2014-04-25T14:45:00Z</dc:date>
    <item>
      <title>cisco ise 1.2 install certificates for ise cluster question</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462381#M86444</link>
      <description>&lt;P&gt;hello all i have an ise cluster of 4 devices. 1 primary admin/secondary monitor, 1 secondary admin/primary admin and 2 policy nodes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need to install public CA certs on them. can I generate 1 CSR on one of the nodes, that includes a SAN with the DNS names of all the nodes?&lt;/P&gt;&lt;P&gt;Therefore get only 1 cert from the CA, and export and import the same cert into all the other nodes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or do i have to generate 1 CSR for each node and purchase 4 certs? Wild card certs is not an option. tHANKS,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:40:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462381#M86444</guid>
      <dc:creator>west33637</dc:creator>
      <dc:date>2019-03-11T04:40:06Z</dc:date>
    </item>
    <item>
      <title>ISE allows you to install a</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462382#M86445</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;ISE allows you to install a certificate with multiple Subject Alternative Name (SAN) fields. A browser reaching the ISE using any of the listed SAN names will accept the certificate without any error as long as it trusts the CA that signed the certificate.&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;The CSR for such a certificate cannot be generated from the ISE GUI. http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/113675-ise-binds-multi-names-00.html&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;Cisco ISE checks for a matching subject name as follows:&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;1. Cisco ISE looks at the subject alternative name (SAN) extension of the certificate. If the SAN contains one or more DNS names, then one of the DNS names must match the FQDN of the Cisco ISE node. If a wildcard certificate is used, then the wildcard domain name must match the domain in the Cisco ISE node's FQDN.&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;2. If there are no DNS names in the SAN, or if the SAN is missing entirely, then the Common Name (CN) in the Subject field of the certificate or the wildcard domain in the Subject field of the certificate must match the FQDN of the node.&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;3. If no match is found, the certificate is rejected.&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;Regards,&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&lt;SMALL&gt;&lt;CITE&gt;&lt;Q&gt;&lt;SAMP&gt;&lt;KBD&gt;&lt;SPAN style="font-size:11px;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/KBD&gt;&lt;/SAMP&gt;&lt;/Q&gt;&lt;/CITE&gt;&lt;/SMALL&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 06:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462382#M86445</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-04-25T06:57:17Z</dc:date>
    </item>
    <item>
      <title>Yes, I agree with Jatin.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462383#M86446</link>
      <description>&lt;P&gt;Yes, I agree with Jatin. Please see what SAN is and how it is useful&lt;/P&gt;&lt;P&gt;The Subject Alternative Name field :&lt;/P&gt;&lt;P&gt;Subject Alternative Names let you protect multiple host names with a single SSL certificate.&lt;/P&gt;&lt;P&gt;Subject Alternative Names allow you to specify a list of host names to be protected by a single SSL certificate.&lt;BR /&gt;Secure host names on different base domains in one SSL Certificate. A wildcard certificate can protect all first-level subdomains on an entire domain, such as *.example.com. But a wildcard cannot protect both &lt;A href="https://community.cisco.com/www.example.com" target="_blank"&gt;www.example.com&lt;/A&gt; and www.example.net.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 07:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462383#M86446</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-04-25T07:52:47Z</dc:date>
    </item>
    <item>
      <title>Hello Jatin. Thanks for the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462384#M86447</link>
      <description>&lt;P&gt;Hello Jatin. Thanks for the response. It was very helpful. You mentioned that the CSR cannot be generated from the ISE GUI. I believe that in 1.2 you can add the SAN DNS to the CSR in the GUI.&lt;/P&gt;&lt;P&gt;Im not sure if that document is referring to an older version? Can you confirm this? Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462384#M86447</guid>
      <dc:creator>west33637</dc:creator>
      <dc:date>2014-04-25T14:45:00Z</dc:date>
    </item>
    <item>
      <title>Yes, you're correct. The</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462385#M86448</link>
      <description>&lt;P&gt;&lt;FONT face="verdana, geneva, sans-serif"&gt;&lt;SPAN style="font-size: 11px;"&gt;Yes, you're correct. The document was created prior to ISE 1.2. You can&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.333333015441895px;"&gt;generate&lt;/SPAN&gt;&lt;SPAN style="font-size: 11px;"&gt;&amp;nbsp;CSR from the ISE GUI and add SAN.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-install-certificates-for-ise-cluster-question/m-p/2462385#M86448</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-04-25T14:57:05Z</dc:date>
    </item>
  </channel>
</rss>

