01-29-2019 09:51 AM - edited 03-11-2019 01:54 AM
Hi, I posted a similar question about certificates but, this is more of do I need to have the EAP CSR signed....
I have a small ISE 2.4 install with Windows 10 clients. On the client side in windows we are not checking the "validate server certificate". I know this is necessarily not secure. If that is the case do I still need to generate a CSR and get the EAP certificate signed by a CA? Can I just leave it binded to the default self signed certificate if I'm not validating it in windows?
Thanks,
Dan
Solved! Go to Solution.
01-29-2019 04:02 PM
You can use the default self-signed ISE cert for the EAP role. But I would still create a new CSR for a self-signed cert and make it valid for 5 years or so. Because out of the box, ISE certs are only valid for 1 year. Just do it now and save yourself the toruble later on. Remember that the EAP cert can be handled separately from the other roles like Admin, Web Portals etc. Creating a new EAP cert won't restart any services.
01-29-2019 04:02 PM
You can use the default self-signed ISE cert for the EAP role. But I would still create a new CSR for a self-signed cert and make it valid for 5 years or so. Because out of the box, ISE certs are only valid for 1 year. Just do it now and save yourself the toruble later on. Remember that the EAP cert can be handled separately from the other roles like Admin, Web Portals etc. Creating a new EAP cert won't restart any services.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide