<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failover NAC Server with CA cert - Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-nac-server-with-ca-cert-help/m-p/1489161#M738347</link>
    <description>&lt;P&gt;Hi everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN&gt;I have worked with projects of NAC, but recently working with Failover have some doubts.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;Speaking in an easy to understand exactly what processes to configure failover with certificates generated by CA?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;1 - CA to be the domain?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Let's take an easy example:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;I Have CAS01 (real ip) and CAS02 (real IP)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;2 - CAS01 I access the tab "X509 Certification Request" and generate CSR with the information:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;CN = CAS.domain; CAS = (ip service)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;3 - I selected the private key + Certificate request and click in Export (save)= CSR.pem Certificate request generated by CAS01 and import this file to the CA in which will generate the certificate.cert (based on the CSR and the private key CAS01).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;4 - After the file certificate.cert in hand, I care for this CAS01 (X509 Certificate tab) + root.cert (CA = certificate of Trusted Certificate Authorities tab).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;5 - I'll do the failover configurations in this tab to complete steps in CAS01.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;------------------------------------------CAS02 ----------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Now come the questions:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;According to documentation, I use the same certificate+privatekey and care for the CAS02.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;But when I do this because I had message like "private key not found".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text"&gt;&lt;SPAN style="background-color: #fff;"&gt;In others case, when I exported the&amp;nbsp; certicate + private key(CAS01 - x509 certificate TAB) and Imported to the CAS02, the CAS02 takes the IP Service and CAS01 and CAS02 were inaccessible.&amp;nbsp; : 0 &lt;/SPAN&gt;&lt;SPAN style="color: #000; background-color: #e6ecf9;"&gt;What is the correct way when using certificates generated by CA??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000; background-color: #e6ecf9; "&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #fff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ebeff9;"&gt;We can describe in detail the processes in CAS02??&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;Is there any case incorrect in CAS01??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:03:19 GMT</pubDate>
    <dc:creator>Tiago Andrade de Paula</dc:creator>
    <dc:date>2020-02-21T12:03:19Z</dc:date>
    <item>
      <title>Failover NAC Server with CA cert - Help</title>
      <link>https://community.cisco.com/t5/network-security/failover-nac-server-with-ca-cert-help/m-p/1489161#M738347</link>
      <description>&lt;P&gt;Hi everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN&gt;I have worked with projects of NAC, but recently working with Failover have some doubts.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;Speaking in an easy to understand exactly what processes to configure failover with certificates generated by CA?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;1 - CA to be the domain?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Let's take an easy example:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;I Have CAS01 (real ip) and CAS02 (real IP)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;2 - CAS01 I access the tab "X509 Certification Request" and generate CSR with the information:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;CN = CAS.domain; CAS = (ip service)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;3 - I selected the private key + Certificate request and click in Export (save)= CSR.pem Certificate request generated by CAS01 and import this file to the CA in which will generate the certificate.cert (based on the CSR and the private key CAS01).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;4 - After the file certificate.cert in hand, I care for this CAS01 (X509 Certificate tab) + root.cert (CA = certificate of Trusted Certificate Authorities tab).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;5 - I'll do the failover configurations in this tab to complete steps in CAS01.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;------------------------------------------CAS02 ----------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Now come the questions:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;According to documentation, I use the same certificate+privatekey and care for the CAS02.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;But when I do this because I had message like "private key not found".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text"&gt;&lt;SPAN style="background-color: #fff;"&gt;In others case, when I exported the&amp;nbsp; certicate + private key(CAS01 - x509 certificate TAB) and Imported to the CAS02, the CAS02 takes the IP Service and CAS01 and CAS02 were inaccessible.&amp;nbsp; : 0 &lt;/SPAN&gt;&lt;SPAN style="color: #000; background-color: #e6ecf9;"&gt;What is the correct way when using certificates generated by CA??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000; background-color: #e6ecf9; "&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #fff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ebeff9;"&gt;We can describe in detail the processes in CAS02??&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;"&gt;Is there any case incorrect in CAS01??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-nac-server-with-ca-cert-help/m-p/1489161#M738347</guid>
      <dc:creator>Tiago Andrade de Paula</dc:creator>
      <dc:date>2020-02-21T12:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Failover NAC Server with CA cert - Help</title>
      <link>https://community.cisco.com/t5/network-security/failover-nac-server-with-ca-cert-help/m-p/1489162#M738376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tiago,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please reveiw this document first: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://bit.ly/aGr7bw"&gt;http://bit.ly/aGr7bw&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case of CA signed certificates, you would follow the same procedure. The only difference is that before you start installing the certificate, make sure that the root certificate from the CA is installed in the Trusted Certificate Authorities of both the CASs. Once that is in place, generate the cert from one CAS, and then install the pvk+cert on both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 14:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-nac-server-with-ca-cert-help/m-p/1489162#M738376</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-08-16T14:45:01Z</dc:date>
    </item>
  </channel>
</rss>

