04-19-2017 05:14 PM
Hey guys, with HTTPS certs in ISE we can use a SINGLE certificate on all ISE nodes and use the SAN field in the certificate to match each ISE nodes hostname. This is good as a single certificate for guest HTTPS sessions across the whole ISE deployment.
My questions is; can you also do this for EAP? In other words, use a single EAP certificate across all ISE nodes and leveraging the SAN fields within the certificate. Not sure if this is either recommended or supported, but keen to here some feedback.
Thanks
DJ
Solved! Go to Solution.
04-19-2017 05:23 PM
Sure, we may apply the same to that for EAP. In case you have read it, I would recommend How To: Implement ISE Server-Side Certificates
04-19-2017 05:23 PM
Sure, we may apply the same to that for EAP. In case you have read it, I would recommend How To: Implement ISE Server-Side Certificates
04-19-2017 08:20 PM
Cool - you can use the same EAP cert on all nodes and the CN is not really tied to the ISE FQDN - it can be anything really.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide