Cisco ISE in distributed deployment uses an internal PKI Infrastructure and hierarchy with the Primary PAN as the Root CA in the top of the trust hierarchy and the PSN nodes as the subordinate CA to manage digital certificates for services such as portals, pxGrid and EAP Authentication.
In this real scenario you will demystify with practice certificate management in the Distributed Deployment how the internal PKI infrastructure is created step by step.
See the attachment document.