<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Charles for the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434806#M87362</link>
    <description>&lt;P&gt;Thanks Charles for the response, do I need to purchase Wildcard SSL Certificate to use in Distributed Cisco ISE deployments? Seems that when purchasing wildcard certificate they need the CN field fill up with the wildcard name.&lt;/P&gt;</description>
    <pubDate>Sun, 16 Mar 2014 14:06:55 GMT</pubDate>
    <dc:creator>mjrmontemayor</dc:creator>
    <dc:date>2014-03-16T14:06:55Z</dc:date>
    <item>
      <title>Cisco ISE CSR generation issue with wildcard certificate.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434804#M87360</link>
      <description>&lt;P&gt;We are purchasing SSL Wildcard Certificate to use in Cisco ISE but when I enter the following attributes given by the vendor, I have this error,&lt;/P&gt;&lt;P&gt;"*.domain.com is not a valid wildcard name". The attributes I created in the CSR as follows:&lt;/P&gt;&lt;P&gt;CN=*.domain.com&lt;/P&gt;&lt;P&gt;SAN&lt;/P&gt;&lt;P&gt;DNS Name: ise.domain.com&lt;/P&gt;&lt;P&gt;The above parameters is given by the vendor. They said that I should put this attribute because the CA (DigiCert), only accepts this format to issue wildcard certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The vendor rejected my previous CSR which I successfully created with the following attributes below. This was based on Cisco's Documentation.&lt;/P&gt;&lt;P&gt;CN=ise.domain.com&lt;/P&gt;&lt;P&gt;SAN&lt;/P&gt;&lt;P&gt;DNS Name: ise.domain.com&lt;/P&gt;&lt;P&gt;DNS Name: *.domain.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want to confirm if the attribute given by the vendor are valid for the Cisco ISE to generate CSR. Or must use valid FQDN in the CN entries and not wildcard name. And use the wildcard name only in the SAN DNS Name Entry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advice. Appreciate the prompt respose from the expert.&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:31:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434804#M87360</guid>
      <dc:creator>mjrmontemayor</dc:creator>
      <dc:date>2019-03-11T04:31:21Z</dc:date>
    </item>
    <item>
      <title>Mike,Take a look at the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434805#M87361</link>
      <description>&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;Take a look at the attached files.&amp;nbsp; (Still having issues showing pictures here since they updated the forum).&lt;/P&gt;&lt;P&gt;Long story short, the wildcard goes in the SAN field.&amp;nbsp; I have shown this in the second picture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.&amp;nbsp; Otherwise, feel free to post follow-up questions.&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 17:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434805#M87361</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-03-12T17:55:38Z</dc:date>
    </item>
    <item>
      <title>Thanks Charles for the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434806#M87362</link>
      <description>&lt;P&gt;Thanks Charles for the response, do I need to purchase Wildcard SSL Certificate to use in Distributed Cisco ISE deployments? Seems that when purchasing wildcard certificate they need the CN field fill up with the wildcard name.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Mar 2014 14:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434806#M87362</guid>
      <dc:creator>mjrmontemayor</dc:creator>
      <dc:date>2014-03-16T14:06:55Z</dc:date>
    </item>
    <item>
      <title>Mike, A wildcard cert is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434807#M87363</link>
      <description>&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A wildcard cert is definitely the way to go in a distibuted environment.&amp;nbsp; Use the hostname got your Admin node in the CN field:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN=ise, OU=domain, OU=com&lt;/P&gt;&lt;P&gt;and enter the SAN field as asown above for the CSR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.&amp;nbsp; Otherwise, feel free to post follow-up questions.&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 13:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-csr-generation-issue-with-wildcard-certificate/m-p/2434807#M87363</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-03-17T13:07:57Z</dc:date>
    </item>
  </channel>
</rss>

