You are here
SEC0212 - ISE 2.0 Certificate Provisioning Portal (Part 2)
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video shows you how to configure the new Certificate Provisioning Portal on Cisco ISE 2.0. The video begins with a discussion of a change in internal CA hierarchy. We will then go through portal creation, test certificate web enrolment, and ultimately utilize the obtained certificate in AnyConnect remote VPN authentication.
Part 2 of this lab covers certificate enrolment and AnyConnect VPN authentication testing
Topic:
- ISE Internal CA Hierarchy
- Certificate Provisioning Portal
- Certificate Template
- Certificate Web Enrolment
- AnyConnect VPN with Client Certificate Authentication
3 comments
ISE Intermediate CA eap-tls failure
I do the step according to your video , Config ISE 2.0 as Intermediate CA , and generate another new CSR for EAP authentication, then use client to get cert from client provision portal , but after client get correct client and client chain which is included all cert , but eap-tls failure , so the log from ISE "EAP-TLS failed SSL/TLS handshake because of an unsupported certificate in the client certificate chain" could you tell me why?
CRL
how about the revocation, if I'm using the cert provided by ISE and the user is terminated, how can do I revoke the cert and get the ASA to validate the cert with the ISE ?
the video shows we are decoupling the authC from AuthZ, meaning if we revoke the cert the autheC will still happen ?
thank you, great videos
CRL
Any certificate issued by ISE can be revoked from the Endpoint Certificate page. You then can configure ASA the do cert revocation check against ISE over OCSP, not CRL, as shown in video SEC0213.