What identity is ISE for place on CSR to NDE?

Hello

I'm having a problem with the Service Proxy PEIE of ISE. I based my config on CVD BYOD.

I am able to register for an iPAD to my Board, but by checking the common name of the issued certificate or SAN, I see the service account NDES user/email on the certificate name. According to the documents consulted, I expect to have a reference to the mac address of the device to which the certificate has been generated for or to the user name that triggered the application. None of those who appear on the visible fields on the certificate.

When the authentication workflow debugging, I see that the user name is the Service of NDE account, however, and the RADIUS username is the actual username of the user who triggered the device registration.

Can everyone I would like to know if this is expected behavior, and how he successfully generated certificate and how to set up the model certificate for it/ISE?

Thank you

Gustavo Novais

Gustavo,

I came across this question, I was setting up this feature, I don't have the mac address in the list of the attributes of the cert, but I managed to change the model of the screenshot attached so that the generated certificate was the user name of the authentication request:

I hope this helps!

Tarik Admani
* Please note the useful messages *.

Tags: Cisco Security

Similar Questions

Maybe you are looking for