When wildcard certificates are not allowed, every portal FQDN must be explicitly listed. This requires adding each portal's FQDN to the SAN (Subject Alternative Name) field of the CSR so that the resulting certificate is valid for all ISE portals after signing.