cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
356
Views
0
Helpful
2
Replies

Installing a Third-Party CA-signed Certificate in ISE - Using OpenSSL?

Ideal Networks
Level 1
Level 1

Good afternoon, we need to install a 3rd party public CA certificate on an ISE PSN for EAP authentication only (EAP-PEAP)

The ISE PSN is currently to configured with a .local domain suffix (company.local)

As a result, we cannot generate a CSR on this PSN matching the companies public FQDN (company.com)

Common name in the cert would be ise.company.com.

Question: To avoid changing the domain suffix of the ISE PSN to company.com so that we can generate a CSR to be signed by a public CA, is it possible to simply create the CSR in OpenSSL, have it signed and then imported into ISE?

What i am unsure of is whether a publically signed certificate would need to be binded to a CSR generated on the PSN or whether the approach outlined above using OpenSSL would work and we keep the domain suffix of the PSN as company.local?

Assume this would be ok providing that we had the original private key used to generate the CSR?

Regards

1 Accepted Solution

Accepted Solutions

@Ideal Networks you can import certificates in to ISE that have been generated off box, you will have to import the certificate and private key.

View solution in original post

2 Replies 2

@Ideal Networks you can import certificates in to ISE that have been generated off box, you will have to import the certificate and private key.

Ideal Networks
Level 1
Level 1

Thank you @Rob Ingram appreciate the response.

Regards