07-07-2017 08:04 AM
Hi,
I try to setup ISE as RA and using our existing Microsoft SCEP server for Apple Mac device. I got RA cert and SCEP configured on ISE follow this guide: ISE - Adding Certificates to ISE and Creating Certificate Profiles .
I also configured the Certificate template and pointing to our external SCEP server. But when I try to use Certificate provisioning portal, it doesn't allow me to select this template. only allow me to select internal SCEP template. Is this current ISE limitation (ISE 2.1 Patch3)? How can I use this template for our device cert provisioning?
Solved! Go to Solution.
07-08-2017 08:04 PM
On macOS, after we download the network setup assistant app and run it, it will contact ISE for the profile, which will use the template and trigger the certificate enrollment. The following how-to guides are based on ISE 1.1.1 but they have relevant info on how this is done:
How To: ISE & BYOD: Using Certificates For Differentiated Acces
How To: ISE & BYOD: Onboarding, Registering & Provisioning
Also check out the other resources @ BYOD
07-07-2017 08:07 AM
here is the portal: Couldn't see the template pointing to external SCEP
07-07-2017 10:53 AM
ISE can issue certificates via SCEP during the BYOD flow, not for manual certificate provisioning via certificate portal. ISE Cert portal is for issuing certificates from ISE internal CA. If you want to get certificates from MS CA, you should connect to MS CA portal, which is typically http(s)://CERTSERVER_IP/certsrv/
07-07-2017 11:39 AM
if we use external SCEP follow the BYOD flow, when will the certificate request send to SCEP server? Is the NSP template with Certificate template triggering the Certificate enrollment? Or somewhere else control it ?
i got confused here ...
07-08-2017 08:04 PM
On macOS, after we download the network setup assistant app and run it, it will contact ISE for the profile, which will use the template and trigger the certificate enrollment. The following how-to guides are based on ISE 1.1.1 but they have relevant info on how this is done:
How To: ISE & BYOD: Using Certificates For Differentiated Acces
How To: ISE & BYOD: Onboarding, Registering & Provisioning
Also check out the other resources @ BYOD
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide