cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
335
Views
0
Helpful
2
Replies

ISE 2.2 Certificates

Andy Guley
Level 1
Level 1

The certificates on my ISE servers expire at the end of June.  I have two nodes that are doing authentication.  The certificates will be used for EAP and wireless.  We have a windows PKI setup and will be getting the certificates from that server.

 

If my client machines have the Root and Intermediate cert do they need the cert that is installed on the ISE servers for EAP as well?  The current cert doesnt appear on the windows machines.  

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Usually not required. Please check the settings for [ ] Verify the server's identity by validating the certificate and Trusted Root Certificate Authorities in the EAP properties of the Windows supplicants. They might have been defined and enforced via a GPO. See Certificate issues with RADIUS connection on W10 clients

View solution in original post

2 Replies 2

hslai
Cisco Employee
Cisco Employee

Usually not required. Please check the settings for [ ] Verify the server's identity by validating the certificate and Trusted Root Certificate Authorities in the EAP properties of the Windows supplicants. They might have been defined and enforced via a GPO. See Certificate issues with RADIUS connection on W10 clients

Windows and Android can be made to relax the rule to not care about the Radius server cert.  But just because you can do this doesn't mean it's a good idea. In fact it's a very bad idea.  You're allowing someone to perform a man in the middle attack by potentially spoofing the Radius server (with the hacker's, since your clients don't care to whom they are connecting).  Bad news in my opinion.  

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: