cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

722
Views
5
Helpful
1
Replies
Shinpei Kono
Cisco Employee

ISE 2.6 Patch 2 - Certificate Portal authorization for external admin

Having a thing to make clarification regarding external(AD) admin users for Certificate Portal to create certificate(s) to others.


From Portal Settings, I have selected AD as Authentication Search List and then chose a specific AD Group as Authorization method. The access to the portal is granted and the admin is able to generate a cert for its own acount at this point.

I have then tried mapping the AD Group to Super Admin privilege by creating new Admin Group (selected the AD Group as External Groups) and applying it to new RBAC permission which has 'Super Admin Menu Access' and "Super Admin Data Access" but I am still unable to create certificate(s) to others.

If I created shadow user identical to AD account and set password type as AD in Network Access User, created Admin User from it, gave Super Admin or ERS Admin, everything seemed to work as my customer wanted.

All the observations above are expected and should we use shadow user in this scenario?

1 ACCEPTED SOLUTION

Accepted Solutions
howon
Cisco Employee

Yes, use the shadow admin account with AD password to create certificate with different CN.

View solution in original post

1 REPLY 1
howon
Cisco Employee

Yes, use the shadow admin account with AD password to create certificate with different CN.

View solution in original post

Create
Recognize Your Peers
Polls
Which of these topics should we host an event in the Community?

Top Choice: ISE Demo (100%)

Content for Community-Ad

ISE Webinars



Did you miss a previous ISE webinar?

CiscoISE YouTube Channel