Phase 3: Certificate Management

Identity in a FIPS-compliant ISE deployment is built on a foundation of strong, trusted certificates. This phase covers the lifecycle of certificates used for both managing the ISE nodes (Admin) and for the network devices to identify themselves to ISE (Device).

Understanding the Certificate Hierarchy

To establish trust, you must understand the relationship between the different certificates:

  1. Root CA (Certificate Authority): The ultimate source of trust. All certificates in your environment should eventually trace back to this Root.
  2. Intermediate CA: Often used to issue certificates to end-entities (like ISE nodes), providing an extra layer of security.
  3. End-Entity Certificates: These are the actual certificates installed on your ISE nodes and network devices.

Generating System Certificate CSRs

Instead of importing a pre-made certificate, the most secure method is to have the ISE node generate its own Certificate Signing Request (CSR). This ensures the private key never leaves the ISE appliance.

  1. Navigate to Administration > System > Certificates > Certificate Signing Requests.
  2. Create New Request: Select the node and the purpose (e.g., Admin or EAP Authentication).
  3. Enter Details: Provide the required information (Common Name, Organization, etc.). The Common Name (CN) should match the FQDN of the ISE node.
  4. Generate: Complete the wizard to produce the CSR.
  5. Submit to CA: Export the CSR and submit it to your Certificate Authority for signing.

Importing Trusted Certificates

For ISE to trust certificates presented by clients or network devices, it must possess the corresponding Trusted Root and Intermediate certificates.

  1. Navigate to Administration > System > Certificates > Trusted Certificates.
  2. Import Certificate: Select the certificate file (usually in .pem or .cer format) provided by your CA.
  3. Configure Trust Settings:
    • Trust for Authentication: Check this if the certificate will be used to verify the identity of a client or device.
    • Trust for EAP: Check this if the certificate is part of an EAP-based authentication flow.
  4. Repeat: Perform this for both your Root CA and any Intermediate CAs in your chain.

Creating Certificate Authentication Profiles (CAPs)

A Certificate Authentication Profile (CAP) tells ISE how to look at a certificate to decide if it's valid for authentication.

  1. Navigate to Administration > Identity Management > External Identity Sources > Certificate Authentication Profile.
  2. Create New: Provide a descriptive name (e.g., CAP_Internal_CA).
  3. Define Mapping: Specify which fields in the certificate ISE should use to identify the user/device (e.g., Subject Alternative Name (SAN) or Common Name (CN)).
  4. Save: This profile is now ready to be used in your Authentication Policies.

Binding Certificates

Generating a CSR is only half the battle; you must "bind" the signed certificate back to the ISE node so it can actually use it.

  1. Navigate to Administration > System > Certificates > Certificate Management.
  2. Identify the Node: Select the node and the specific certificate type (e.g., Admin or EAP).
  3. Import Signed Certificate: Upload the signed certificate returned by your CA.
  4. Complete Binding: Follow the prompts to associate the certificate with its intended role.

Verification: Once bound, verify the certificate status in the Certificate Management dashboard to ensure it is "Valid" and not expired.