cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2661
Views
0
Helpful
4
Replies

Common Name (CN) in certificate in ISE

Lucas Woo
Level 1
Level 1

Hello.

I want to issue Client certificate for employee in ISE

Each employee have to import Client Certificate into there Windows/Mac PC,
but I can`t enter employee's name and this error message is displayed.

ise_cn.jpg

The image is like this.
-------
Mike
Dave
Bob
Smith



-------

I tried to enter the name "Mike", but after entering it specific error message was displayed.

I don`t know the subject the employee's name are displayed.

1 Accepted Solution

Accepted Solutions

Arne Bier
VIP
VIP

Hi @Lucas Woo 

 

If you are logging in as a non-admin user (e.g. mike, bob, etc) then the subject common name must be the same as the username that was used to login (e.g. mike). This is a security feature to stop regular users from creating certificates that do not belong to them. 

 

The admin user can create certificates on behalf of an user - this is a highly privileged process and must be done by a trusted admin only.

I can't recall right now how to tell the ISE portal which Group of users is admin - perhaps others can help out. I have used this in lab scenarios only to quickly create certs for users - but I log in as each user to create those certs.

 

View solution in original post

4 Replies 4

Arne Bier
VIP
VIP

If you are logging in as a non-admin user (e.g. mike, bob, etc) then the subject common name must be the same as the username that was used to login (e.g. mike). This is a security feature to stop regular users from creating certificates that do not belong to them. 

 

The admin user can create certificates on behalf of an user - this is a highly privileged process and must be done by a trusted admin only.

I can't recall right now how to tell the ISE portal which Group of users is admin - perhaps others can help out. I have used this in lab scenarios only to quickly create certs for users - but I log in as each user to create those certs.

 

Arne Bier
VIP
VIP

Hi @Lucas Woo 

 

If you are logging in as a non-admin user (e.g. mike, bob, etc) then the subject common name must be the same as the username that was used to login (e.g. mike). This is a security feature to stop regular users from creating certificates that do not belong to them. 

 

The admin user can create certificates on behalf of an user - this is a highly privileged process and must be done by a trusted admin only.

I can't recall right now how to tell the ISE portal which Group of users is admin - perhaps others can help out. I have used this in lab scenarios only to quickly create certs for users - but I log in as each user to create those certs.

 

Charlie Moreton
Cisco Employee
Cisco Employee

Administration > Device Portal Management > Certificate Provisioning

 

Expand Portal Settings, select the Identity Source Sequence to be used. If needed, you can also select groups from that ISS to act as adminsCPP_ISS.png 

Arne Bier
VIP
VIP

thanks @Charlie Moreton - I will give that a whirl next time I am testing this out. I was using the ISE internal identity store and I was unable to assign any "admin" attribute to an internal ISE user. I guess I missed the part about using that ISS