03-26-2025 03:13 AM
In the past I have used multi-use CSR's for Admin and EAP authentication. I am now going to use individual CSR's for Admin and EAP authentication for renewal. I have the admin CSR signed, but what options on the CA do I use to sign the EAP Authentication CSR? When they were combined I think I just used webserver and then everything else was default.
Solved! Go to Solution.
03-26-2025 03:24 AM
Are we feeling pretty good about this? The linked document just glosses over the signing process in step 6. as "Submit it to your CA for signature" and then moves directly to installing the signed certificate back into ISE.
03-26-2025 05:36 AM
I just made a case for this.
03-26-2025 03:18 AM
@SERS-techsupport you should be fine using the same CA template to sign the EAP certificate that is used to sign the Admin certificate.
03-26-2025 03:24 AM
Are we feeling pretty good about this? The linked document just glosses over the signing process in step 6. as "Submit it to your CA for signature" and then moves directly to installing the signed certificate back into ISE.
03-26-2025 05:36 AM
I just made a case for this.
03-26-2025 05:42 AM - edited 03-26-2025 10:24 AM
@SERS-techsupport yes, if using Windows Certificate Authority you can use the "Web Server" certificate template for the EAP certificate, same as you can use for Admin certificate. Example.
Cisco would state whether specific certificate attributes are required. The only ISE certificate that requires specific certificate attributes (therefore not the Web Server template) is the pxGrid certificate.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide