cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1222
Views
6
Helpful
8
Replies

Wilcard Certificate for Cisco ISE admin portal

mikeyasg
Level 1
Level 1

Hi,

I was using a CA signed wildcard certificate for the Admin portal of Cisco ISE. it was succesfully installed but when i browse to the admin portal it shows not secure certificate is not valid. i stil can see the wildcard certificate in the certificate details of the browser. i already imported the certificate including the intermediate certificate in my windows trusted certificates folder. the certificate is also imported into Cisco ISE trusted certificates. is there anything that i sld be doing?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

@mikeyasg You are accessing your ISE admin web portal by its FQDN. Right? In case you are using IP, it can give hostname match error. If the issuing CA is well-known, its root CA should already be trusted by Windows unless you are using older versions of client OS and there might be an issue with SHA-1/SHA-2 compatibility.

As you are unlikely to share the screenshots of the certificate hierarchy and the browser errors, please consider engage Cisco TAC.

View solution in original post

8 Replies 8

Try a different browser?  Does the wildcard name match the DNS name of ISE?

The wild card certificate that I imported to ISE is like *.domain.com and the FQDN of the ISE is ISE.domain.com 

Is it upper case? ISE FQDNs should always be lower case. Case sensitive operating systems will not trust this.

It’s lowercase the autocorrect is messing up my writing. But fqdn is not included in the cert I just imported the CA signed wildcard and assigned it for the admin.

Landen
Level 1
Level 1

A wildcard certificate is a type of digital certificate that can be used to secure multiple subdomains within a domain. In the context of Cisco ISE (Identity Services Engine), a wildcard certificate can be used to secure the administration portal, which is used to manage and configure the ISE system.

To configure a wildcard certificate for the Cisco ISE admin portal, you will need to follow these general steps:

  1. Obtain a wildcard certificate from a trusted certificate authority (CA)
  2. Import the certificate and private key into Cisco ISE
  3. Configure Cisco ISE to use the imported certificate for the admin portal

It is important to note that you should always verify the authenticity of a certificate before importing it into Cisco ISE, and also to follow the correct steps for importing a certificate.

I did the same on my website : https://goappsplay.com/blackmartapk/

What I did is the same as you stated  

hslai
Cisco Employee
Cisco Employee

@mikeyasg You are accessing your ISE admin web portal by its FQDN. Right? In case you are using IP, it can give hostname match error. If the issuing CA is well-known, its root CA should already be trusted by Windows unless you are using older versions of client OS and there might be an issue with SHA-1/SHA-2 compatibility.

As you are unlikely to share the screenshots of the certificate hierarchy and the browser errors, please consider engage Cisco TAC.

Thank You @hslai i forgot to use the FQDN to access the portal.