Current State:
2x Admin Nodes
2x Monitoring and Logging Nodes.
2x Policy Nodes (Clustered)
Environment is running using self-signed certificates (copied from all nodes to all other nodes).
Future State:
I want to replace the self-signed certificates with certificates generated from the Cisco ISE CA. I want to split out the functionality of these certificates into separate certs for Admin/pxGrid/etc. I also want to use the Cisco ISE CA as my internal CA for device management of other systems (routers/switches/firewalls/servers). We do not have a MS CA that we can use.
What I've done so far:
1. Generated CSRs for all Servers/functions.
2. Created a Certificate Provisioning Portal.
Issues:
It appears that the Certificate Provisioning Portal is geared more towards user-based certificate generation. The templates don't allow me to create a template for FQDN or anything server related. Is there a different portal (URL) that I need to be using to generate server certificates?