03-14-2013 05:32 AM - edited 03-10-2019 08:11 PM
Hi,
to grant not to show the certificate error adevertise to all clients connecting to guest services (because obviously they don't have the CA root certificate of our company), we have purchased a wildcard certificate from Verisign in order to work with all of our PSN Common Names and friendly url for sponsor and mydevices. But when I try to import it to more than one PSN the following error message is shown " The certificate already exists in the data base".
How can I import the same certificate (with the same private key) in every PSN in a node group?
We have ISE 1.1.2
Thanks in advance!!
Luis
03-14-2013 04:58 PM
You can't. Ise does not support wildcard certs. You need san certificates for each ise node.
Sent from Cisco Technical Support Android App
03-14-2013 09:16 PM
Here is a good guide provide by TAC, please use this as a reference.
http://www.cisco.com/en/US/products/ps11640/products_tech_note09186a0080bd0953.shtml
Thanks,
Tarik Admani
*Please rate helpful posts*
03-19-2013 10:55 AM
Rumor has it that ISE 1.2 (or later) will support wildcard certs.
Until then, you'll have to use SAN certs like Jan has suggested.
04-25-2013 05:56 PM
Hello All,
ISE software also uses openssl. Though upto ISE 1.1.x interface does not provide with a field for SAN (Subject Alternative Name), but it should support wildcard certificates. It is just the interface that does not facilitate certificate and CSR generation. So we need to generate the certificate and CSR by explicit use of openssl. Tarik has already provided the link which can be of valuable assistance.
As far as wildcard certificate support is concerned, ISE 1.2 would definitely support this feature. This is confirmed
03-08-2017 10:26 PM - edited 04-12-2018 06:10 AM
Thanks for sharing link
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide