cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
290
Views
0
Helpful
1
Replies

on prem ISE deployment using AWS certs

tachyon05
Level 5
Level 5

The max lifespan for public certs is being shortened in a phased reduction, and in a few years the certs will only be valid for 47 days.  For our on prem ISE deployment, at a minimum, we need a public cert for guest network.  AWS certificate manager (ACM) seems to offer a secure and automated alternative.  Can anyone who configured their Cisco ISE to use ACM certs share their experience or How To?  Can ACM certs work with 100% on prem ISE deployment?

1 Reply 1

Assuming they are just like any regular certificate sure. But this is where a lot of customers are pivoting away from ISE guest to SaaS platform, LWA, or just an open network. ISE has no ACME or other automatic certificate re-enrollments so the ISE admin will need to manually update that public cert every 45 days, not ideal.