<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: certificate issue while integrating FTD with ISE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329818#M1064114</link>
    <description>&lt;P&gt;The PC that I use to request the certificate is not a member of the domain but CA server is. I don't understand in which part I need to provide admin privilege. I even entered &lt;STRONG&gt;http://localhost/Certsrv&lt;/STRONG&gt; on the CA server too but there was no option for Template again.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Feb 2018 06:37:21 GMT</pubDate>
    <dc:creator>ciscoworlds</dc:creator>
    <dc:date>2018-02-13T06:37:21Z</dc:date>
    <item>
      <title>certificate issue while integrating FTD with ISE</title>
      <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329302#M1064112</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to integrate FTD 6.2.2 with ISE 2.2 using PxGrid. To do the certification part, I have configured a Win 2008 R2 as my internal CA with just these roles installed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca1.png" style="width: 381px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7447i8D7FFB17D208435D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ca1.png" alt="ca1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://social.technet.microsoft.com/Forums/getfile/1227058" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;This windows machine is member of my internal lab domain. While I enter "http://ipaddress/certsrv"on a client machine (which isn't a member of that domain) and follow "&lt;STRONG&gt;Request a Certificate&lt;/STRONG&gt;" and then click on "&lt;STRONG&gt;Advanced Certificate Request&lt;/STRONG&gt;", the following page appears, but as you can see there is no option to select Certificate Template.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7448iCD10B9C48923FD86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ca2.png" alt="ca2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://social.technet.microsoft.com/Forums/getfile/1227060" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;Documents say that I need to request a certificate which uses "Web Server" certificate template. What&amp;nbsp;did I miss?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329302#M1064112</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2020-02-21T15:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: certificate issue while integrating FTD with ISE</title>
      <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329316#M1064113</link>
      <description>&lt;P&gt;Hi, It's strange that you don't have the dropdown box for the certificates, are you logged in as an administrator with full rights to request cert? Also the "Web Server" certificate you mentioned is not good enough, you'd have to create a new template an ensure the EKU of Server and Client authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively you could use the internal ISE CA to sign the pxGrid certificates &lt;A href="https://communities.cisco.com/docs/DOC-71928" target="_self"&gt;https://communities.cisco.com/docs/DOC-71928&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 13:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329316#M1064113</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-02-12T13:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: certificate issue while integrating FTD with ISE</title>
      <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329818#M1064114</link>
      <description>&lt;P&gt;The PC that I use to request the certificate is not a member of the domain but CA server is. I don't understand in which part I need to provide admin privilege. I even entered &lt;STRONG&gt;http://localhost/Certsrv&lt;/STRONG&gt; on the CA server too but there was no option for Template again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2018 06:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3329818#M1064114</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-02-13T06:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: certificate issue while integrating FTD with ISE</title>
      <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3337255#M1064115</link>
      <description>Any suggestion guys? isn't there anybody who has successfully integrated ISE with FTD?</description>
      <pubDate>Sun, 25 Feb 2018 01:22:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3337255#M1064115</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-02-25T01:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: certificate issue while integrating FTD with ISE</title>
      <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3337291#M1064116</link>
      <description>&lt;P&gt;I have it setup in my lab with a Windows Server 2016 AD DC providing certificate services. I have ISE, FMC, FTD, ESA, WSA, vWLC etc. all running with certificates issued by my DC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's odd to not see the option to select the certificate template on your certsrv page. You should have the option to select a Web server certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are some screenshots from my setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Template management on the CA (Windows Server 2016)" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7966i3B3B71EEBAA5019D/image-size/large?v=v2&amp;amp;px=999" role="button" title="CA Template management.PNG" alt="Template management on the CA (Windows Server 2016)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Template management on the CA (Windows Server 2016)&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Template dropdown from the CA's web UI" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7967iAFCBCB0EC81E1983/image-size/large?v=v2&amp;amp;px=999" role="button" title="CA Template dropdown.PNG" alt="Template dropdown from the CA's web UI" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Template dropdown from the CA's web UI&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Appliances with CA-issued certificates" style="width: 373px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7968i2E4030676AB7B42F/image-size/large?v=v2&amp;amp;px=999" role="button" title="SSL lock icons.PNG" alt="Appliances with CA-issued certificates" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Appliances with CA-issued certificates&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 05:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3337291#M1064116</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-02-25T05:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: certificate issue while integrating FTD with ISE</title>
      <link>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3337353#M1064117</link>
      <description>&lt;P&gt;Hi. I completely removed all of the roles installed on CA server and disconnect it from the domain. Then reinstall the roles from the scratch &amp;amp; rejoin to domain. Now the option is shown there. I don't know what was the problem with Windows, but I'm tired of these stupid unknown Windows issues. Thanks for your replies.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 12:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/certificate-issue-while-integrating-ftd-with-ise/m-p/3337353#M1064117</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-02-25T12:17:43Z</dc:date>
    </item>
  </channel>
</rss>

