09-28-2018 08:16 AM - edited 03-11-2019 01:50 AM
I have a customer that is migrating from an existing external CA to a new external CA. They're currently using their existing CA for EAP-TLS and they want to add the new CA to ISE, so essentially authenticate with both CAs during the migration. Can they just add the cert chain for the new CA, generate and sign a CSR, import the new cert, and mark it to be used for authentication? Is there anything else that needs to be done or any design considerations that they need to be aware of?
09-28-2018 08:44 AM
09-30-2018 12:09 PM
Yes, you can change the ISE cert with the simple import for authentication and it will be fine.
The only other consideration is will your endpoints trust the new cert chain?
If the endpoints do not have the new CA in their trusted store they may reject any authentication attempts from ISE signed by the new CA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide