cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1148
Views
0
Helpful
2
Replies

Unable to import a wildcard cert to the PSN

Jozef Cmorej
Level 1
Level 1

Hello,

 

I would like to import a wildcard cert to one of the PSNs in the DMZ that provides guest access. I can import the cert with the private key to the PAN but not to the rest of the ISE nodes as I cannot select a specific node during the import process.

ISE GUI says:
Wildcard Certificate will be replicated/copied to all nodes in the deployment.
Node selection is hence disabled.

Once I import the certificate to the PAN, I do not see any replication of it to other nodes. Once the guest connects to the guest net, they get still a self-signed cert from the PSN in the DMZ.

I have tried to import the cert to a different portal group tag but it did not work, either.

How can I import the wildcard cert to the specific PSN?

The ISE Deployment:
Version 2.3, distributed environment with several VMs

Thank you.

 

2 Replies 2

howon
Cisco Employee
Cisco Employee

You can login to individual node GUI and manage the certificates. If this is just for the guest portal you should be able to simply assign the wildcard certificate to a portal tag (Or default) and then assign the tag to the guest portal to take affect. I've noticed certain version of ISE node may require restart to take affect after the portal tag update.

hslai
Cisco Employee
Cisco Employee

Besides what howon said,

We may un-check the selection [ ] Allow Wildcard Certificates, and import the key and cert to each of individual nodes.

Note that the certificate needs either a wildcard domain entry (e.g. *.aSLD.aTLD) in either in CN or as a DNS entry in SAN. Also known issues -- CSCvn62923, CSCvg36087, CSCvg36122, and CSCve29595.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: