cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
560
Views
0
Helpful
2
Replies

ISE handles a different certificate domain

Leo TI
Level 1
Level 1

Hello
I have a question. We need to use EAP authentication. To start, ISE is on the ise.example.com domain, but I need my users to use other.net. Is this feasible?
When generating the CSR, should I choose to use EAP and use ise.other.net?

2 Replies 2

Enes Simnica
Level 5
Level 5

gDay to u @Leo TI and yes, that’s feasible. For EAP, the certificate’s CN/SAN must match the domain clients expect. If ur users belong to other.net, then the CSR should use ise.other.net (or include it in the SAN). U can also add multiple SANs if u need the ISE node reachable under both domains. Just make sure the certificate chain is trusted by the clients; otherwise EAP authentication will fail.....

hope it helps and enjoy ur weekend!!

 

-Enes

more Cisco?!
more Gym?!



If this post solved your problem, kindly mark it as Accepted Solution. Much appreciated!

Rich R
VIP
VIP

And remember your clients will need DNS resolution for that domain, so just make sure you're allowed to configure DNS records on the other.net domain.  Otherwise you need to use your own registered domain.