<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot download CRL to my ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340168#M110777</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ise 1.2,&amp;nbsp; i have configured everything normally and i can browse to my CRL from any windows pc that is ok,&amp;nbsp; but still my ise cannot download the CRL, i get the following error on my ISE. please help me im totally stuck in this.&amp;nbsp;&amp;nbsp; i have standalone CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ise error msg&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Alarms: CRL Retrieval Failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Description:&amp;nbsp; &lt;BR /&gt;Unable to retrieve CRL from the server. This could occur if the specified url is unavailable.&lt;/P&gt;&lt;P&gt;Suggested Actions: &lt;BR /&gt;Please ensure that the download url is correct and is available for the service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could not download Certificate Revocation List for certificate with CN=TrustedCA&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:58:10 GMT</pubDate>
    <dc:creator>Imran Ahmad</dc:creator>
    <dc:date>2019-03-11T03:58:10Z</dc:date>
    <item>
      <title>Cannot download CRL to my ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340168#M110777</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ise 1.2,&amp;nbsp; i have configured everything normally and i can browse to my CRL from any windows pc that is ok,&amp;nbsp; but still my ise cannot download the CRL, i get the following error on my ISE. please help me im totally stuck in this.&amp;nbsp;&amp;nbsp; i have standalone CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ise error msg&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Alarms: CRL Retrieval Failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Description:&amp;nbsp; &lt;BR /&gt;Unable to retrieve CRL from the server. This could occur if the specified url is unavailable.&lt;/P&gt;&lt;P&gt;Suggested Actions: &lt;BR /&gt;Please ensure that the download url is correct and is available for the service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could not download Certificate Revocation List for certificate with CN=TrustedCA&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340168#M110777</guid>
      <dc:creator>Imran Ahmad</dc:creator>
      <dc:date>2019-03-11T03:58:10Z</dc:date>
    </item>
    <item>
      <title>Cannot download CRL to my ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340169#M110778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;Certificate Revocation List Configuration area, do the&amp;nbsp; following: &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1053547"&gt;&lt;/A&gt;&lt;STRONG&gt;a. &lt;/STRONG&gt;&lt;IMG alt="http://www.cisco.com/en/US/i/templates/blank.gif" height="2" src="https://community.cisco.com/" width="10" /&gt;Check the &lt;STRONG&gt;Download CRL&lt;/STRONG&gt; check&amp;nbsp; box for the Cisco ISE to download a CRL. &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1053549"&gt;&lt;/A&gt;&lt;STRONG&gt;b. &lt;/STRONG&gt;&lt;IMG alt="http://www.cisco.com/en/US/i/templates/blank.gif" height="2" src="https://community.cisco.com/" width="10" /&gt;Enter the URL to download the CRL&amp;nbsp; from a CA in the URL Distribution text box. This field will be&amp;nbsp; automatically populated if it is specified in the certificate authority&amp;nbsp; certificate. The URL must begin with "http" or "https." &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1053550"&gt;&lt;/A&gt;The CRL can be downloaded&amp;nbsp; automatically or periodically. &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1053551"&gt;&lt;/A&gt;&lt;STRONG&gt;c. &lt;/STRONG&gt;&lt;IMG alt="http://www.cisco.com/en/US/i/templates/blank.gif" height="2" src="https://community.cisco.com/" width="10" /&gt;You can configure the time interval&amp;nbsp; between downloads in minutes, hours, days, or weeks if you want the CRL&amp;nbsp; to be downloaded automatically before the previous CRL update expires. &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1053556"&gt;&lt;/A&gt;&lt;STRONG&gt;d. &lt;/STRONG&gt;&lt;IMG alt="http://www.cisco.com/en/US/i/templates/blank.gif" height="2" src="https://community.cisco.com/" width="10" /&gt;Configure the time interval in&amp;nbsp; minutes, hours, days, or weeks to wait before the Cisco ISE tries to&amp;nbsp; download the CRL again. &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1053557"&gt;&lt;/A&gt;&lt;STRONG&gt;e. &lt;/STRONG&gt;&lt;IMG alt="http://www.cisco.com/en/US/i/templates/blank.gif" height="2" src="https://community.cisco.com/" width="10" /&gt;If you uncheck the Bypass CRL&amp;nbsp; Verification if CRL is not Received check box, all client requests that&amp;nbsp; use certificates signed by the selected CA will be rejected until Cisco&amp;nbsp; ISE receives the CRL file. If you check this check box, the client&amp;nbsp; requests will be accepted before the CRL is received. &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="wp1098509"&gt;&lt;/A&gt;&lt;STRONG&gt;f. &lt;/STRONG&gt;&lt;IMG alt="http://www.cisco.com/en/US/i/templates/blank.gif" height="2" src="https://community.cisco.com/" width="10" /&gt;If you uncheck the Ignore CRL that&amp;nbsp; is not yet valid or expired check box, Cisco ISE checks the CRL file for&amp;nbsp; the start date in the Effective Date field and the expiration date in&amp;nbsp; the Next Update field. If the CRL is not yet active or has expired, all&amp;nbsp; authentications that use certificates signed by this CA are rejected. If&amp;nbsp; you check this check box, Cisco ISE ignores the start date and&amp;nbsp; expiration date and continues to use the not yet active or expired CRL&amp;nbsp; and permits or rejects the EAP-TLS authentications based on the contents&amp;nbsp; of the CRL. &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For complete&amp;nbsp; configuration, please check the below link.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_cert.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 16:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340169#M110778</guid>
      <dc:creator>aqjaved</dc:creator>
      <dc:date>2013-10-07T16:03:24Z</dc:date>
    </item>
    <item>
      <title>Cannot download CRL to my ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340170#M110779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Imran,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check to make sure that the CA services are up and running on the CA server.&lt;/LI&gt;&lt;LI&gt;Replace the certificate. For a trust certificate, contact the issuing Certificate Authority (CA). For a CA-signed local certificate, generate a CSR and have the CA create a new certificate. For a self-signed local certificate, use Cisco ISE to extend the expiration date. You can delete the certificate if it is no longer used.&lt;/LI&gt;&lt;LI&gt;Check if the configuration change is expected. &lt;/LI&gt;&lt;LI&gt;Ensure that the download URL is correct and is available for the service. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;For more information, please visit the given link:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_mnt.html"&gt;&lt;STRONG&gt;http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_mnt.html&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 05:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340170#M110779</guid>
      <dc:creator>Muhammad Munir</dc:creator>
      <dc:date>2013-10-08T05:13:36Z</dc:date>
    </item>
    <item>
      <title>Cannot download CRL to my ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340171#M110780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CRL Retrieval Failed ---- Unable to&amp;nbsp; retrieve CRL from the server. This could occur if the specified CRL is&amp;nbsp; unavailable.--------- Ensure that the download URL is correct and is&amp;nbsp; available for the service.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 20:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340171#M110780</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-10-10T20:17:18Z</dc:date>
    </item>
    <item>
      <title>Cannot download CRL to my ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340172#M110781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have the same issue and believe it is due to the ISE using the system proxy settings. According to the documentation, it should be possible to add exceptions, but I don't see these fields (ISE 1.2 patch 4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1 Choose Administration &amp;gt; System &amp;gt; Settings &amp;gt; Proxy.&lt;/P&gt;&lt;P&gt;Step 2 Enter the proxy IP address or DNS-resolvable host name in Proxy Address, and specify the port through which proxy traffic travels to and from Cisco ISE in Proxy Port.&lt;/P&gt;&lt;P&gt;Step 3 Enter the IP Address or Address range of hosts or domains to be bypassed in Bypass Proxy Settings for these Hosts &amp;amp; Domain.&lt;/P&gt;&lt;P&gt;Step 4 Enter the username and password used to authenticate to the proxy servers in the corresponding fields.&lt;/P&gt;&lt;P&gt;Step 5 Click Save.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 11:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340172#M110781</guid>
      <dc:creator>networks.comms</dc:creator>
      <dc:date>2013-11-27T11:54:56Z</dc:date>
    </item>
    <item>
      <title>Cannot download CRL to my ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340173#M110782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem, my CRL URL contained spaces and looks like ISE has problem with that. OCSP is workaround&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Nov 2013 15:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-download-crl-to-my-ise/m-p/2340173#M110782</guid>
      <dc:creator>Karel Navratil</dc:creator>
      <dc:date>2013-11-28T15:59:59Z</dc:date>
    </item>
  </channel>
</rss>

