09-25-2020 06:44 AM
Does CRL validation require a specific license type in ISE? Thanks.
Solved! Go to Solution.
09-25-2020 08:21 AM
All certificate operations are considered part of the basic AAA authentication / authorization capabilities in the Base license. Authenticating users and endpoints with certs and checking SCEP/CRL validation is included.
Where it probably gets confusing is with BYOD because the BYOD process typically involves provisioning certificates. Provisioning a certificate for BYOD does not actually trigger the 2.x Plus license - it is the use of the EndPoints.BYODRegistration attribute or the RegisteredDevices:* endpoint groups in an authorization rule that will consume Plus licenses.
09-25-2020 08:21 AM
All certificate operations are considered part of the basic AAA authentication / authorization capabilities in the Base license. Authenticating users and endpoints with certs and checking SCEP/CRL validation is included.
Where it probably gets confusing is with BYOD because the BYOD process typically involves provisioning certificates. Provisioning a certificate for BYOD does not actually trigger the 2.x Plus license - it is the use of the EndPoints.BYODRegistration attribute or the RegisteredDevices:* endpoint groups in an authorization rule that will consume Plus licenses.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide