09-09-2020 06:56 PM
I am deploying ISE 2.7. For the EAP certificate is it possible to use a publicly signed certificate then import the same certificate into all of the PSNs? This would simplify things and eliminate devices that are not part of the domain from seeing an untrusted certificate warning.
09-09-2020 08:16 PM
That is actually the recommended approach but the certificate has to be a wildcard certificate. Ensure the Subject/Common Name (CN) is set to one of the ISE nodes' FQDN and then use the wildcard as a SAN DNS Name such as *.mycompany.com. The Subject/CN cannot be a wildcard or Windows clients will complain.
09-10-2020 04:34 AM
Thank you for the reply. The CN would be ise.xyz.local and the wildcard in the SAN would be *.xyz.com. Will this work?
09-10-2020 06:55 AM
That is correct!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide