<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.2 and iPEP Certificate Requirements in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400530#M88553</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Octavian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same requirements apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jan 2014 01:32:46 GMT</pubDate>
    <dc:creator>Javier Henderson</dc:creator>
    <dc:date>2014-01-30T01:32:46Z</dc:date>
    <item>
      <title>ISE 1.2 and iPEP Certificate Requirements</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400529#M88552</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 1.1.x version of ISE, there are some constraints regarding the certificates used for iPEP and Admin:&lt;/P&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Both EKU attributes should be disabled, if both EKU attributes are disabled in the Inline Posture certificate, or both EKU attributes should be enabled, if the server attribute is enabled in the Inline Postur&amp;nbsp; certificate.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080bea904.shtml" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080bea904.shtml&lt;/A&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;Does the same thing applies for iPEP in ISE 1.2? The User Guide for ISE 1.2 and Hardware Installation Guide doesn't mention anything about EKU and specific certificate attributes..&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;Any thoughts? &lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;Thank you,&lt;/LI&gt;&lt;LI&gt;Octavian&lt;/LI&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400529#M88552</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2019-03-11T04:18:46Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 and iPEP Certificate Requirements</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400530#M88553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Octavian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same requirements apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jan 2014 01:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400530#M88553</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2014-01-30T01:32:46Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 and iPEP Certificate Requirements</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400531#M88554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The EKU validation has been removed in version 1.2&lt;/P&gt;&lt;P&gt;"If you configure ISE for services such as Inline&amp;nbsp; Policy Enforcement Point (iPEP), the template used in order to generate&amp;nbsp; the ISE server identity certificate should contain both client and&amp;nbsp; server authentication attributes if you use ISE Version 1.1.x or&amp;nbsp; earlier. This allows the admin and inline nodes to mutually authenticate&amp;nbsp; each other. The EKU validation for iPEP was removed in ISE Version 1.2,&amp;nbsp; which makes this requirement less relevant."&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps11640/products_tech_note09186a0080bff108.shtml"&gt;http://www.cisco.com/en/US/products/ps11640/products_tech_note09186a0080bff108.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jan 2014 05:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-and-ipep-certificate-requirements/m-p/2400531#M88554</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-01-30T05:25:21Z</dc:date>
    </item>
  </channel>
</rss>

