cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
647
Views
0
Helpful
2
Replies

Apply Selfsign certificate to DNA

Ahmed Tarek
Level 3
Level 3

hello all,

i need to apply self signed certificate to DNA, Cisco Support Tac dose not recommeded

any idea?

2 Replies 2

Ahmed Tarek
Level 3
Level 3

any update?

the process you described is to add the self signed certificate to trusted certificate store so that browser will not throw the cert error, that is not really much of security.

If you don't have a PKI infrastructure, just use default cert, it will still allow you to do all integrations with DNAC like ISE, adding devices for management etc. Since your browser do not trust Cisco default signed cert you will continue to get the error message.

Cisco recommends assigning cert before DNAC is in production because if a connection is lost between managed device and DNAC for some reason (such as a power outage or reboot), network devices will need to establish trust with the new CA before connections can be established. 

-hope this helps-