11-24-2016 02:18 PM - edited 03-11-2019 12:15 AM
Hi Experts,
I am trying to configure ISE deployment to provide a PKI service, so that routers can enrol to get their own signed certs. I can't find any documentation on this.
ISE PAN is root CA, and ISE PSN is sub CA. I need an IOS router to be able to pull the root CA from the PAN or PSN, and then enrol using SCEP. Then it should also be able to do a CRL or check validity via OCSP.
If there is another way of doing this, I'm open to it, but would like to know if at all possible on ISE.
Bilal
Solved! Go to Solution.
12-02-2016 03:12 PM
Hello Bilal-
Just to make sure I understand your requirements: You want to use ISE's internal PKI to automatically issue certificates to your IOS Routers via SCEP?
If Yes, then the answer is No :) You can manually generate a CSR and have ISE's CA sign it and then manually install it on the routers. The automatic process for certificate on-boarding is only supported for:
- Windows
- Android
- iOS
- OSX
- ChromeOS
I hope this helps!
Thank you for rating helpful posts!
12-02-2016 03:12 PM
Hello Bilal-
Just to make sure I understand your requirements: You want to use ISE's internal PKI to automatically issue certificates to your IOS Routers via SCEP?
If Yes, then the answer is No :) You can manually generate a CSR and have ISE's CA sign it and then manually install it on the routers. The automatic process for certificate on-boarding is only supported for:
- Windows
- Android
- iOS
- OSX
- ChromeOS
I hope this helps!
Thank you for rating helpful posts!
12-02-2016 11:45 PM
Thats a shame because i quite liked the idea of having ISE being the PKI and only point of trust.
Have it working now with MS 2012 datacenter which was my last resort.
Thank you Neno.
12-03-2016 12:34 PM
Yeah, Cisco's stance is that the internal PKI is for BYOD and not to replace corporate PKI. However, I agree with you that it would be nice to be able to replace a Windows solution as it is easier to work with and the GUI is much nicer. Maybe in the future :)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide