cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
702
Views
0
Helpful
7
Replies

ISE EAP Public certificate for system and Local PKI for Endpoint

SAM1275
Level 1
Level 1

I want to Install public certificate for ISE. and Endpoint must use local PKI certificate for authentication.
is it possible?

1 Accepted Solution

Accepted Solutions

7 Replies 7

@SAM1275 yes, you can use public certificate for EAP on ISE. As long as ISE has the internal root CA installed in ISE, then the client computers can use a certificate issued by the local CA to authenticate using 802.1X.

Obviously the client computers will need to trusted the public certificate use by ISE, but most computers will have the public root certificates installed as default.

Thanks for information.

Just 1 more information i would require.

do we require to host ISE on public network or without also possible?

@SAM1275 no ISE does not need to be hosted on a public network, ISE would be in your internal LAN.

Then how will get public certificate installed on ISE System for EAP authentication?

@SAM1275 The CA would require a public registered domain name in order to sign the certiifcate, however ISE does not need to be hosted in the public network.

You create a certificate signing request (CSR) give this to the public CA to sign and import to ISE.

you are Awesome

What should i fill in CN and SAN?
public domain, but in ise system ip domain configured with local domain name.