11-06-2019 12:52 AM
Hello, can i use Cisco ISE as certificate manager in my network?
I need to install self-signed certificates from multiple not ise servers on user devices when they connecting to network.
Can i do it with ISE? If it possible can somebody share link how to do it ?
Thanks
Solved! Go to Solution.
11-06-2019 02:26 AM
You want to use ISE as an MDM or Group Policy type of system? That's not possible as far as I know.
Not sure why you want to do what you're describing. Installing self-signed certificates on end devices? What are these devices and what do they use the certificates for?
By using the BYOD onboarding tools in ISE you can push certs and profiles to devices, but those certs are created either by ISE itself (Internal CA) or via a SCEP Proxy function to another CA. The SCEP enrollment is performed on the end devices during BYOD and this means that you cannot use ISE to unconditionally push certificates onto a device.
ISE does have a Certificate Self Service Portal option to allow you to create certs using ISE's Internal CA, and then the user can download the cert (and private key) and install that on a target device. But that would be a manual download and install. As far as I know, you can email a certificate to an iPhone and the phone will prompt you to install it. Not sure if that also works for a private key - I kind of doubt it.
11-06-2019 02:26 AM
You want to use ISE as an MDM or Group Policy type of system? That's not possible as far as I know.
Not sure why you want to do what you're describing. Installing self-signed certificates on end devices? What are these devices and what do they use the certificates for?
By using the BYOD onboarding tools in ISE you can push certs and profiles to devices, but those certs are created either by ISE itself (Internal CA) or via a SCEP Proxy function to another CA. The SCEP enrollment is performed on the end devices during BYOD and this means that you cannot use ISE to unconditionally push certificates onto a device.
ISE does have a Certificate Self Service Portal option to allow you to create certs using ISE's Internal CA, and then the user can download the cert (and private key) and install that on a target device. But that would be a manual download and install. As far as I know, you can email a certificate to an iPhone and the phone will prompt you to install it. Not sure if that also works for a private key - I kind of doubt it.
11-06-2019 02:35 AM
Yeah, something around mdm. But due to policies some devices can not be enrolled into MDM.
I want do remove message from web browsers that my internal sites have untrusted certificates. I m trying to create self signed certificate like i am CA and set this devices to trust this certificate automatically. I thought it can be automated by ise.
11-06-2019 03:34 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide