Problem of generation of ISE CSR Cisco with wildcard certificate.

We buy the Wildcard SSL certificate to be used in Cisco ISE but when I enter the following attributes given by the seller, I have this error.

« *. domain.com is not a valid generic name. The attributes that I created in the CSR as follows:

CN = *. domain.com

SAN

DNS name: ise.domain.com

The above parameters is given by the seller. They said I should put this attribute because the certification authority (DigiCert), accepts that this certificate wildcard question format.

The seller rejected my previous CSR I created successfully with the following attributes below. This is based on the Cisco Documentation.

CN = ISE.domain.com

SAN

DNS name: ise.domain.com

DNS name: *. domain.com

I just want to confirm if the attribute given by the seller are valid for the Cisco ISE generate the CSR. Or to use the valid FQDN in the entrances to CN and not the generic name. And use the generic name in the name SAN DNS entry.

Please advice. Appreciate the prompt respose of the expert.

Thank you.

Kind regards

Mike

Mike,

A wildcard cert is definitely the way to go in a distributed environment.  Use the host name the node of your Admin got into the CN field:

CN = ise, OR = domain, OU = com

then enter the SAN field as asown above the CSR.

Please rate useful messages and mark this question as answered if, in fact, does that answer your question.  Otherwise, feel free to post additional questions.

Charles Moreton

Tags: Cisco Security

Similar Questions

  • Question of ISE CWA Cisco

    Nice day

    I have 1.2 ISE Cisco with Cisco 2960 n.

    I set up the authorization of the employee successfully, but my problem is with the users of comments that the link is not redirected.

    Please let know us what I put in the default authentication policy rule? deny access?

    And on the switch, I should put the prompt to connect to specific ports or I have to configure the VLAN specific authorization profile?

    Appreciate your support,

    In your authorization policy, you give your guest Wired the same result as Wired-Webauth.

    First time through you don't know he is invited so that it hits Wired-Webauth and gets redirected. Second time you need him in comments feed, so that you know that he is a guest authenticated, it hits Wired-Guest, but you send the same permissions 'Web_Auth '. Create a profile that you want to offer your guests authenticated - Guest_Allowed for example.

  • ISE CSR not displayed

    I have a monitor main ISE node that the server certificate has expired.  I generated a new CSR and he pointed out that it has been created and can be found under the tab of certificate signing requests but it never showed up.  Tried to re - generating, but he now States that already exist.  Restarted the unit to see if that would solve the problem but the CSR doesn't show always.  For a test, I created another CSR using the ip address of the device as CN; and again, it was reported that she could be considered, but is not displayed on the tab of the CSR.  These are journal items when I created the initial CSR sees it when I tried to create a new one using the same CN. The ISE version is 1.1.3.124.  I could create CSR and update certificates on the nodes of the Administration and policies.

    237 INFO 2014 - 09 - 22 11:43:07, 237 [http-443-29] [] cpm.admin.infra.action.LocalCertAddAction - signing certificate request DC-ISE-2_int_fhfa_gov #PID _NAC3315$-SVR___$ _VID$ _V01$ _SN$ _KQ586M0___ has been successfully created. 2014-09-22 11:43:16,

    ERROR 174 2014-09-22 11:44:33, 174 [http-443-29] [] cpm.admin.infra.action.LocalCertAddAction - unable to import the certificate: com.cisco.cpm.infrastructure.certmgmt.api.CertMgmtException: resource name ' NAC group: NAC:CertificateRequests:DC - EHT-2_int_fhfa_gov #PID _NAC3315$-SVR___$ _VID$ _V01$ _SN$ _KQ586M0___' already exists. 2014-09-22 11:44:36,

    Thank you

    It's been a while since I used this version of ISE, but I remember having similar problem. The only way I believe that told us to remove this was to recreate the picture on the box or get involved TAC where they can use a root access and remove the 'object' which is stuck in the database. A number of things, you can try this:

    1 generate the CSR using another application such as open ssl

    2. try upgrading to version 1.2 ISE and see if that clears the DB

    Thank you for evaluating useful messages!

  • ISE of Cisco protocols for ldap and Windows wireless client

    Only protocols below are supported by ise in combination with ldap identity sources.

    EAP - GTC, PAP, EAP - TLS, PEAP-TLS.

    Peripheral Mac OS appear to be able to use these, but Windows users seem to have problems. How windows users must connect with ise that only uses the ldap Protocol?

    You can use the anyconnect Network Access Manager. Just out of curiosity why ldap on join ise to AD?

    Sent by Cisco Support technique Android app

  • Cisco ise 1.2 installation of certificates for the issue of cluster ise

    Hello everyone I have a cluster ise 4 devices. 1 main admin/secondary monitor, admin of admin/primary secondary 1 and 2 knots of policy

    I need to install the Cert CA public on them. can I generate 1 CSR on one of the nodes, which includes a San with all the nodes DNS names?

    So get 1 single certificate by the CA and export and import the cert even in all other nodes?

    or do I have to generate 1 CSR for each node and 4 certificates of purchase? Wildcard certificates is not an option. Thank you

    Yes, you are right. The document was created before ISE 1.2. You can generate the CSR from the interface of ISE and add SAN.

    Kind regards

    Jatin kone

    * Make the rate of useful messages *.

  • Problem of event reminder of the registry with Linkam ActiveX controls

    Hello

    I have a problem in configuration reference VI to interface with Linkam ActiveX control with an event callback function to register. I created a VI strictly typed with re-entrant execution, with all the correct connectors, as shown in the picture below, but LabView complains of a broken wire. The only difference between the input and the output seems to be that the result stands as an asynchronous function, and the entrance wants (synchronous) normal function? I can't find any option to make my VI reference become synchronous. Does anyone have any suggestions as to what to try next? Thank you very much

    Davide

    Hello

    Make a right-click on the terminal 'Ref VI' choose 'create the callback VI '.

    Do not try to build it yourself, it never works. :-)

  • Problem with the certificate on Xbox 360 system Internet Explorer error

    Original title: that is this "problem with certificates?

    I have been using Bing on my Xbox 360 Internet Explorer system for years with little trouble. Today, I cleaned the history since he was a little slow again, but now I am unable to connect to Bing (or really any Microsoft site) through the Xbox 360 Internet Explorer. Whenever I try, I keep coming to a screen message saying that there is a problem with the certificate on the site. I am able to log in and connect to these same sites fine on my computer, but I don't have access to my computer all the time, so it was nice to be able to use Bing on my Xbox 360, but now with this error I can't. What is the cause of this, and what can be done to remedy this.

    It seems that a recent patch for the application of EI on the Xbox 360 has solved this problem now.

  • I have a problem of access to the Outlook account and other pages because appears "certificate error" what's happened with these certificates?

    I have a problem of access to the Outlook account and other pages because appears "certificate error" what's happened with these certificates? Help please.

    There are two main reasons for the mistakes of certificate:

    1. Your computer's time is not set correctly.  Check your time year/month/day/hour/minute/timezone/light of day.  Right-click on the clock in your taskbar and select "set Date/time" and make sure you are ready approximately 5 minutes of real time (don't forget time zone and DST).
    2. The second reason is that Windows XP is not very good for updating root certificates.  Go to the following site:
         <>http://support.Microsoft.com/kb/931125 >
      and go down to the section:
      'Update Package root (designed for Windows XP only)'
      There is a link, you can use to download a update for your root certificates package.  Download this package and double-click it to update.

    HTH,

    JW

  • I have problems connecting my laptop to the TV with 2 ft HDMI connection. Whenever I try to connect "Windows cannot detect tvwizard2ft.exe" appears.

    tvwizard2ft.exe

    I have problems connecting my laptop to the TV with 2 ft HDMI connection. Whenever I try to connect "Windows cannot detect tvwizard2ft.exe" appears.

    Download and install the latest graphics driver. Visit the website of intel to get that. Once downloaded unzip the file and search for tvwsetup.exe.Run this file.

    You may also download and install .NET Framework 3.0 (SP2)

  • Hello, I get the beginning of the muse of adobe are the error message that the adobe application manager is damaged or not installed now, I downloaded 2 times and installed the problem persists, however, can me someone here with a rat page

    Hello

    I get the beginning of the muse of adobe, the error that the application manager adobe is damaged or not installed

    Now, I downloaded 2 times and installed the problem remains, however

    can someone here with rat page

    Kindly try to remove Adobe Application Manager to help cleaning tool and remove CC help | Uninstall the creative desktop application Cloud can download and install Adobe Creative Cloud apps.

  • I have problems to download from a Web site with more than 100 pages. The download is stuck at 6%. Muse has a page limit? I use Adobe Muse CC 2014 v7.4

    I have problems to download from a Web site with more than 100 pages. The download is stuck at 6%. Muse has a page limit? I use Adobe Muse CC 2014 v7.4

    425 is the error that you have been doing all along? That looks like a firewall or router problem or a server side hosting configuration problem.

  • I want to go back to the previous version of 2014.2.  .3 is far too buggy and full of error messages. Create problems because I'm on a timeline with my client and I don't have time to fool around with all the problems.

    2014.3 is far too buggy and full of error messages. Create problems because I'm on a timeline with my client and I don't have time to fool around with all the problems.

    You don't mention what you have encountered errors? Workaround for the problem more frequently reached here is Re: error in Muse: object UID:U6875 has two (or more) owners: U3633 and U3165

    If you have a copy of your .muse file that has not been saved by using 2014.3, you can downgrade by uninstalling Muse, and then choose the previous Version in the drop-down list of filters in the Panel of Apps from the desktop creative cloud application. There will be a popup next to the Muse, where you can select a version prior to install.

  • Various problems of generation of the index

    Hello

    I try to generate the index for my book, I was layoutet with InDesign.

    Now, I am facing two problems.

    Problem 1: Page numbers are wrong. The first two pages of the book, the cover and the backsite of it, has all the numbers and so the introduction to the book begins with "page 1". I solved this with the chapters. Now, if I'm looking for the title of page 43 of the index I see "Headline... page 45." This is because InDesign also has coverage and its backsite.

    Problem 2: If I separated a cap with the key Enter it will appear twice as different entries in the index. If I separate a cap with shift + enter InDesign destroyed the index and also separates the title on two lines, but only as one input connected. But in addition it stretches the entries in the index above the full line because of justification.

    All solutions

    Concerning

    maxpd

    How to sequence the show on the pages Panel pages? Have you started a new article on page 1?

  • Why people have suddenly begun to report their entire question in the place that is intended for a brief description of the problem.  Is there something inherently wrong with the new format of format?

    ... Only to repeat it once again here.

    Why people have suddenly begun to report their entire question in the place that is intended for a brief description of the problem.  Is there something inherently wrong with the new format of format?

    Ahhh, now I see.

    The man, who is just really, really bad design forum.

    I know that it will hurt, Adobe, but you will be away to Jive at a given time.  You're going to have to, as Jive moves further and further away from the ease of use.  So... Dick.22 now, or le.45 later.

  • problem with the certificates on SAA

    Hello

    I am trying up\a tunnell of remote access with an ASA which is natted behind a Checkpoint firewall. Shared key works perfectly, but when I try with client certificates abandons the connection because that;

    482 16:30:34.581 10-27-05 Sev = WARNING/3 IKE/0xE3000080

    Invalid Remote certificate ID: ID_IPV4_ADDR: ID = 0x02001EAC, certificate = 0 x 00000000

    It is the private address 172.30.0.2 instead of the external address. I tried to add the ip address in the registration process, but it won't. Th CA is a company MS CA. the model is a CERT offline ipsec, that I tried to add the IP address for the FQDN name, changing the cn to the ip address, but nothing helped. I think I need to add the ability to add the ip address for the microsoft model, but don't know how to do... any ideas appreciated

    Thank you

    Vincent

    ISAKMP identify auto

    Identity automatically determined by the type of connection: IP address for pre-shared key and Cert DN for Cert-based connections

    That should do it.

Maybe you are looking for

  • How to send frames to header + 1 byte of data in network LIN?

    Hello I use USB-8476 to communicate to a slave in a LIN network. Can someone tell me how I can send a header file more 1 byte of data to the slave in a LIN network. I need to send a sync + id 00 X 34 break, followed by a byte of data. I don't know ho

  • PID change of range change P param too?

    Hello I have a very general question on the PID control. (I have the pid toolkit) I have a process value is measured (PV, it's the temperature), and I have a fixed setpoint. The output of the PID readers regulator current source (Keithley 2400 source

  • HP wireless 6500 Office Jet won't a copy has been working fine until today.

    iMac operating system has nothing to do with it that I'm just trying to make a copy. Just changed ink now when the problem started. It won't always make a copy I just get a blank page. No changes of any kind. no error message. Thank you.

  • Accidentally erase my administrator account what to do.

    I remove my account administrator by mistake now into a separate account and hit a new account, the administrator password appears I can not put a password in question, he won't let me at all not even update my computer.

  • BEFSR41 corrupt 4.3, don't reset, please help

    Posting here because I waited an hour for help on-line and finally abandoned (during the 1 in the queue). A few months ago, I bought a v4.3 BEFSR41 to connect computers to my family (3) together and all be able to use the internet at the same time wi