02-14-2025 08:59 PM
I need your valuable hints to find a solution to my problem. The clients must request a certificate to be able to use the network with dot1x using ISE.
I have a Certificate Authority (CA) server on Windows 2019 (will upgrade soon to 2022). The Certificate Web Enrollment is unsuitable because it's based on ActiveX and has not been updated for many years. I have clients with macOS and Linux. I am looking for a on-premise solution to provide a feasible certification request for them.
Would you please tell me what your suggested solution is ?
02-14-2025 11:46 PM
If you have any Windows clients, they can be issued certificates automatically via AD Group Policy. macOS clients are best managed with an enterprise management tools like Jamf or Kanji.
I have not used it, but you may be able to use a third party solution like SCEPman (https://docs.scepman.com/) to manage all three client types.
02-15-2025 01:29 AM
@imanv to add to what @Marvin Rhoads has already mentioned, if you require an on-premise solution to distribute certificates to the MacOS/Linux devices, you could use the bulit-in ISE CA, this allows the user to login to a portal to request the certificate to use for authentication. An MDM would be the better solution though.
02-15-2025 02:32 AM - edited 02-15-2025 02:43 AM
@Marvin RhoadsThank you very much.
In fact I have separate domain for non-corporate users. The users are not joined to the domain. I use it just for VPN polices.
@Rob IngramThanks for your hint. I think it is possible to configure ISE as subordinate Certificate server with Microsoft CA.
Would please describe a little bit more about the MDM application you may be used for on-premise deployment ?
02-15-2025 02:43 AM
@imanv yes you can configure ISE as a subordinate of the external CA. https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_basic_setup.html#task_E458E69FA39941BBAA9799AAD7FDC644
Some guides on the certificate provisioning portal.
http://labminutes.com/sec0212_ise_20_certificate_privisioning_portal_1
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide