<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - posture fails in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109244#M199755</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use below link for future perspective :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://techzone.cisco.com/t5/Identity-Services-Engine-ISE/Posture-Services-on-the-Cisco-ISE-Configuration-Guide/ta-p/221702"&gt;https://techzone.cisco.com/t5/Identity-Services-Engine-ISE/Posture-Services-on-the-Cisco-ISE-Configuration-Guide/ta-p/221702&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Aug 2013 14:30:03 GMT</pubDate>
    <dc:creator>manjeets</dc:creator>
    <dc:date>2013-08-22T14:30:03Z</dc:date>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109236#M199681</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a problem at the posture checking phase. NAC agent fails to check for posture compliance and remediation never takes place. The client browser is beeing redirected to the following URL: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ise.xxxx.yy:8443/guestportal/gateway?sessionId=AC16FA49000000778BF9058D&amp;amp;action=cpp" target="_blank"&gt;https://ise.xxxx.yy:8443/guestportal/gateway?sessionId=AC16FA49000000778BF9058D&amp;amp;action=cpp&lt;/A&gt;&lt;SPAN&gt;, and then to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ise.xxxx.yy:8443/auth/provisioning/evaluate" target="_blank"&gt;https://ise.xxxx.yy:8443/auth/provisioning/evaluate&lt;/A&gt;&lt;SPAN&gt; (shown below)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/5/3/127351-ise_posturefail.png" alt="ise_posturefail.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Obviously there is a problem on ISE box, missing something. What could be the cause of the problem?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kreso&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109236#M199681</guid>
      <dc:creator>kpanduric</dc:creator>
      <dc:date>2019-03-11T03:02:07Z</dc:date>
    </item>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109237#M199688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please review the below link which might be&amp;nbsp; helpful: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_pos_pol.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_pos_pol.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 23:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109237#M199688</guid>
      <dc:creator>vikasyad</dc:creator>
      <dc:date>2013-05-14T23:20:59Z</dc:date>
    </item>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109238#M199695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vikas,&lt;/P&gt;&lt;P&gt;thank you for the hint.&lt;/P&gt;&lt;P&gt;I have followed the procedure several times but still have the issue.&lt;/P&gt;&lt;P&gt;The TAC case has been opened and for two months I have received only few replies. The problem could be in the certificate issued by the local CA on the AD domain, but as I have not received neither solution nor workaround I can't move forward.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 08:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109238#M199695</guid>
      <dc:creator>kpanduric</dc:creator>
      <dc:date>2013-05-17T08:56:04Z</dc:date>
    </item>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109239#M199705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi kreso,&lt;/P&gt;&lt;P&gt;Have you got solution from TAC. I also face same issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 07:39:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109239#M199705</guid>
      <dc:creator>Najeeb Mohammad</dc:creator>
      <dc:date>2013-07-04T07:39:25Z</dc:date>
    </item>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109240#M199715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try using self signed certificate that will clear the picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Pankaj &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 07:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109240#M199715</guid>
      <dc:creator>pankaj29in</dc:creator>
      <dc:date>2013-07-04T07:59:18Z</dc:date>
    </item>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109241#M199726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;as the TAC engineer and developer said, the problem is in the CA root certificate that was imported in DER format.&lt;/P&gt;&lt;P&gt;Try exporting the root CA certificate (not the one issued to the ISE node by the CA,&amp;nbsp; but the one that is in the Certificate Store), convert it from PKCS#7,DER to X509,PEM format, delete the old CA root cert and import the one you just got as a result of conversion.&lt;/P&gt;&lt;P&gt;You will need some Linux/UNIX box with OpenSSL tools installed. Suppose you exported the original cert to file named cert1.pem, when you try to read it using the following command, you get an error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # openssl x509 -in cert1.pem -inform DER -text&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unable to load certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;following some ASN error messages. To convert it use the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; openssl pkcs7 -inform der -in cert1.pem -print_certs &amp;gt; cert2.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you can read cert data using the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; openssl x509 -inform pem -in cert2.pem -noout -text&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The file cert2.pem is the one that should be imported as a root CA certificate into the Certificate Store on ISE.&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Kreso&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 10:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109241#M199726</guid>
      <dc:creator>kpanduric</dc:creator>
      <dc:date>2013-07-04T10:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109242#M199736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kreso,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your valuable input, problem got solved now. Instead of using openssl we re issued the CA certificate from the local CA and uploaded to ISE ceritification store. The issue was with the old CA certificate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks alot.&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najeeb &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 15:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109242#M199736</guid>
      <dc:creator>Najeeb Mohammad</dc:creator>
      <dc:date>2013-07-04T15:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109243#M199745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pankaj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem got solved, it was the issue of CA Certificate . Thanks for your quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najeeb&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 15:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109243#M199745</guid>
      <dc:creator>Najeeb Mohammad</dc:creator>
      <dc:date>2013-07-04T15:23:15Z</dc:date>
    </item>
    <item>
      <title>ISE - posture fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109244#M199755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use below link for future perspective :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://techzone.cisco.com/t5/Identity-Services-Engine-ISE/Posture-Services-on-the-Cisco-ISE-Configuration-Guide/ta-p/221702"&gt;https://techzone.cisco.com/t5/Identity-Services-Engine-ISE/Posture-Services-on-the-Cisco-ISE-Configuration-Guide/ta-p/221702&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 14:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-fails/m-p/2109244#M199755</guid>
      <dc:creator>manjeets</dc:creator>
      <dc:date>2013-08-22T14:30:03Z</dc:date>
    </item>
  </channel>
</rss>

