<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Certicates - Windows 2003 CA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284338#M826880</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://technet.microsoft.com/en-us/library/cc780649" target="_blank"&gt;http://technet.microsoft.com/en-us/library/cc780649&lt;/A&gt;(WS.10).aspx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Jun 2009 12:46:39 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2009-06-17T12:46:39Z</dc:date>
    <item>
      <title>NAC Certicates - Windows 2003 CA</title>
      <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284333#M826875</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me if/how to generate/install a Certificate from our internal windows based certificate authority.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have redundant CAM and CAS and need to deploy to a production environment but the only certificate is the default perfigo that the appliances come with.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284333#M826875</guid>
      <dc:creator>r.robins</dc:creator>
      <dc:date>2020-02-21T11:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Certicates - Windows 2003 CA</title>
      <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284334#M826876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you really should read the documentation guides for this info.  the nac appliances are very sensitive to the order in which certificates are installed in the larger process of a nac deployment.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's what i usually do though:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. create self-generated certs (which also creates a CSR) using the information you want to be put into the final cert (same hostname, IP, etc etc)&lt;/P&gt;&lt;P&gt;(since you're using HA, be sure to create a CSR based on the SHARED IP or hostname) &lt;/P&gt;&lt;P&gt;2. export CSR and private key from one CAM and one CAS&lt;/P&gt;&lt;P&gt;3. use CSR to request cert from 3rd party cert vendor&lt;/P&gt;&lt;P&gt;4. import requested cert into both CAMs and CASs, and import the private key to the other CAS/CAM whose CSR was not used to request 3rd party cert&lt;/P&gt;&lt;P&gt;5. import root cert of 3rd party cert vendor into all appliances&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...from here, you can configure HA and add the CAS to the CAM in the orders outlined in the config guides.  READ IT VERY CAREFULLY.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone else have anything to add?  its been awhile so i might be leaving a step or two out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6128/products_installation_and_configuration_guides_list.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6128/products_installation_and_configuration_guides_list.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jun 2009 18:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284334#M826876</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-06-16T18:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Certicates - Windows 2003 CA</title>
      <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284335#M826877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I may have been a lttle vague.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our internal CA server has a root cert from verisign, what we want to do is create a cert for the NAC appliances on our own CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible, if so how ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 07:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284335#M826877</guid>
      <dc:creator>r.robins</dc:creator>
      <dc:date>2009-06-17T07:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Certicates - Windows 2003 CA</title>
      <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284336#M826878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can still use youur internal CA to issue certs, but in CA terms, unless you paid for the correct cert, your internal CA server is not a 'subordinate' CA for verisign.  but as long as all your pc's going through nac have the domain root cert installed, it should avoid the SSL Cert warning you would otherwise get.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 11:53:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284336#M826878</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-06-17T11:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Certicates - Windows 2003 CA</title>
      <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284337#M826879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me how to do this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 11:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284337#M826879</guid>
      <dc:creator>r.robins</dc:creator>
      <dc:date>2009-06-17T11:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Certicates - Windows 2003 CA</title>
      <link>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284338#M826880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://technet.microsoft.com/en-us/library/cc780649" target="_blank"&gt;http://technet.microsoft.com/en-us/library/cc780649&lt;/A&gt;(WS.10).aspx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 12:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-certicates-windows-2003-ca/m-p/1284338#M826880</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-06-17T12:46:39Z</dc:date>
    </item>
  </channel>
</rss>

