cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
160
Views
1
Helpful
4
Replies

ISE Dot1.x Certificates and OCSP

netops4
Level 1
Level 1

So I'd like to use ISE to authenticate then authorise a device based on an external CA presented during 802.1x. I'd also like ISE to use an OCSP check for the validity of this cert.

What are the steps to get this to work? Do i need to import the root ca into ISE? How do i configure ISE to use OCSP?

What would the authentication match statement look like?

 

 

4 Replies 4

@netops4 you import the root certificate to ISE "trusted certificates" under that certificate you configure certificate status validation to use OCSP.

For AuthC match you can match on EAP-TLS, for AuthZ you can match on an attribute from the certificate (certificate template, issuer etc).

If you want to perform a lookup against AD you can also use a Certificate Authentication Profile (CAP).

If its a distributed deployment of ISE. Is it just a case of literally importing the root ca to the Primary Admin node? Or do i need to do somehow get the cert onto all the PSNs too?

You just need to do that on the PAN.