03-13-2023 04:12 AM
Hi all,
I have a query; currently we have ISE set up where end users get authenticated via certificate issued by a CA that will soon be defunct.
So I want to set up a few (Test) end-users to authenticate their Certificate from another CA authority, and once thats ok, then migrate all users to the new CA Certificate. Can someone guide me with correct steps in doing this. I have a fear that when I add in the new CA Cert then all exisitng end users may have a problem.?
All help much appreciated
03-13-2023 04:32 AM
Hi all,
I have a query; currently we have ISE set up where end users get authenticated via certificate issued by a CA that will soon be defunct.
So I want to set up a few (Test) end-users to authenticate their Certificate from another CA authority, and once thats ok, then migrate all users to the new CA Certificate. Can someone guide me with correct steps in doing this. I have a fear that when I add in the new CA Cert then all exisitng end users may have a problem.?
All help much appreciated
03-13-2023 06:05 AM
ISE should have new CA Certs, and Client need to have Root and end cert to be published to clients (for testing some users) - thorugh group policy or any other method you have.
Check below guide to configure new Certificate :
03-13-2023 07:02 AM
Hi there,
Our users will get their root and cert published to clients via Active Directory etc. So I am assuming I need to get new Root CA and install it into "Trusted Certs" section and that should be it???
03-15-2023 07:23 PM
yes correct, you need to add the ISE Trust store and also clients should accept the same cert, you can do testing with test device by adding new cert before you going to do a mass deployment to all clients
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide