cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
0
Helpful
4
Replies

ISE - EAP Authentication Certificate

kkillby
Level 1
Level 1

I am looking to replace the Certificate that is assigned to the EAP Authentication Role - However the question has come up:

 

Can this be a Public Certificate such as one signed by GoDaddy or does it need to be signed by the same CA that our Users get their Certificates from which is an internal Microsoft CA?

 

Thanks

 

1 Accepted Solution

Accepted Solutions

Surendra
Cisco Employee
Cisco Employee
It can be a public CA signed certificate as long as that CA’s certificates are present in the Client’s Trusted Root CA certificate store.

View solution in original post

4 Replies 4

Surendra
Cisco Employee
Cisco Employee
It can be a public CA signed certificate as long as that CA’s certificates are present in the Client’s Trusted Root CA certificate store.

Thank you - So we can use an external CA Certificate for EAP Authentication Role on ISE whislt the clients use our internal PKI for EAP-TLS Authentication.

Yes. Both of them need not be from the same CA as long as they trust each other.

Thank you for confirming - I was finding conflicting information.  I will be making this change once back from vacation.