cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
222
Views
1
Helpful
3
Replies

Is it possible to issue computer certificates using ISE internal CA ?

masaad
Level 1
Level 1

Hello,

I need to issue computer certificates to be used for EAP-FAST machine authentication but unfortunately site has issues with MS CA so I'm wondering if I can use ISE internal CA to do the same task ? I know there is certificate provisioning portal but it seems it issue user certificates only. 

Regards,

Mahmoud

 

3 Replies 3

Why EAP-FAST?  Why not TEAP?  Why use Cisco Secure Client NAM at all?  The ISE internal CA is only designed for BYOD use-cases.  It should not be used for an enterprise CA.  I would focus efforts on fixing the issues with MS Active Directory Certificate Services.

ccieexpert
Spotlight
Spotlight

I think i managed to do it for a difficult customer a while back but as mentioned earlier by other poster, it is not designed nor recommended. there is no option to renew a cert etc... best to use a MS internal CA that is what majority of customer use especially if you have a windows machines or use a MDM/intune..

Marvin Rhoads
Hall of Fame
Hall of Fame

Possible - yes. Recommended - definitely not. As others mentioned already, it's not what the ISE CA is designed to do.

It's MUCH easier to just build a new Windows CA and issue certificates from it.