<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037056#M200616</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;i have followed the steps in the guide , still not working. &lt;/P&gt;&lt;P&gt;can you please explain how to create """&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;"&gt;2. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;" width="10" /&gt;&lt;/P&gt;&lt;P&gt;Construct a PEM-encoded X.509 certificate chain""" ????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Sep 2012 04:53:28 GMT</pubDate>
    <dc:creator>syedaltaf.shah</dc:creator>
    <dc:date>2012-09-19T04:53:28Z</dc:date>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037046#M200447</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;we have installed new temporary certificate on our CAM &amp;amp; CAS, but now the clients (Agents) needs to be updated with the same certificate.&lt;/P&gt;&lt;P&gt;every time i restart PC it asks for certificate and i have to accept and install the new certificate on each PC, we have 4k PCs.&lt;/P&gt;&lt;P&gt;is there anyway to push this certificate on all agents from CAM ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037046#M200447</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2019-03-11T02:32:33Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037047#M200454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try to push a GPO in order to push the CAS temp certificate. Do you have an internal CA to issue the right cert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also depending on what version you are on, the self signed cert is only good for 90 days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 14:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037047#M200454</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-13T14:28:29Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037048#M200468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have generated this certificate from NAC Manager and imported on both of NAC Servers, But now clients asking for this certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i have to push this same certificate usgin GPO?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2012 04:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037048#M200468</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-16T04:35:46Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037049#M200483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is one way but it is not the best way since you are essentially pushing a self signed certificate and are making the design of PKI a lot more challenging than it should be. I assume you run active directory (by referring to GPO)? If so, why dont you add the certificate authority role to one of your domain controllers and use autoenrollment so that all your member machines are given a certificate. Not only does this help push the root certificate out to all your clients. It helps you have an internal pki where you can issue certs to your CAM and CAS and can use a root CA to manage the trusts between these applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2012 07:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037049#M200483</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-16T07:15:09Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037050#M200502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tariq,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are using one of our AD as CA for our organization, i tried to import the CA issued by AD but it is not importing, the NAC server is giving me error No Private Key found etc.&lt;/P&gt;&lt;P&gt;Can you please guide me step by step how to do that?&lt;BR /&gt; i will replace all the Certificates on NAC Server &amp;amp; Manager. do i have to install new certificates issued by CA ?&lt;BR /&gt;If you can polease tell me step by step shall be very thankful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2012 07:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037050#M200502</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-16T07:37:07Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037051#M200516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;The guide &lt;A href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/cam48ug.pdf"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/cam48ug.pdf&lt;/A&gt;&lt;BR /&gt; here is v much confusing. first it says export CSR and import the Certificate to Server then it says import PEM to CAM. ?&lt;BR /&gt;is it like this ?&lt;BR /&gt;1. Export CSR from both CAM &amp;amp; CAS ? get 2 seperate certificates fro both ???? and import the corresponding certificates to each other ?&lt;/P&gt;&lt;P&gt;or i have to export one certificate request from cas or CAM and import the certificate issued by CA to both of them ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2012 08:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037051#M200516</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-16T08:26:25Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037052#M200530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since these are two separate servers you will have to generate a csr for the manager and the server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then export both csr and submit them the ca for signing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this you will need to download the certificate in pem format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Install the root certificate in the trusted certificate authority section on both the cas and cam.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Install the signed certificates on the cam and cas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure if you created the csr using dns name that there it is the fqdn and that it is resolvable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this clears your confusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As always please remember to rate any posts that are helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2012 13:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037052#M200530</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-16T13:37:20Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037053#M200553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok, the CA is windows server and there is no option to download PAM format.&lt;/P&gt;&lt;P&gt;2nd what do you mean by root certificate ?&lt;/P&gt;&lt;P&gt;This is what i have done so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Created CSR from CAS &amp;amp; CAM and sent to CA, after they have sent me both the certificates and installed both in CAS &amp;amp; CAM respectively with adding the Private Key (editing the cert file and pasting the private key after the cert)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Now NAC Servers connected to CAM &amp;amp; are on HA Also. but client agents are not doing any activity. it looks like NAC Agents are disconnected or disable or idle. ???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 05:28:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037053#M200553</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-17T05:28:11Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037054#M200568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;dear tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any clear documentation for installing the certificate on CAM &amp;amp; CAS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just to make it correct. below the configuration which i did for creating CSR&lt;/P&gt;&lt;P&gt;CN: CAM IP ADDRESS&lt;/P&gt;&lt;P&gt;OU: NetworkSecurity&lt;/P&gt;&lt;P&gt;O: MOL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and in CAS i have give the CN: CAM IP Address aswel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please correct me if any mistake.&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 06:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037054#M200568</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-17T06:40:08Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037055#M200606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i though i responded a long time ago. Here are the guides:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAM - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cam/m_admin.html#wp1078189"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cam/m_admin.html#wp1078189&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAS - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cas/s_admin.html#wp1040111"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cas/s_admin.html#wp1040111&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 21:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037055#M200606</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-18T21:44:51Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037056#M200616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;i have followed the steps in the guide , still not working. &lt;/P&gt;&lt;P&gt;can you please explain how to create """&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;"&gt;2. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;" width="10" /&gt;&lt;/P&gt;&lt;P&gt;Construct a PEM-encoded X.509 certificate chain""" ????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 04:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037056#M200616</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-19T04:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC, CAM &amp; CAS New certificate. agents needs to be upd</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037057#M200632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to open your certificates with a notepad or word pad.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Starting with server cert you will copy and paste the intermediate and then the root cert and then save. Then upload to the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 05:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037057#M200632</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-19T05:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC, CAM &amp; CAS New certificate. agents needs to be upd</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037058#M200647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed here is a good write up n how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.digicert.com/ssl-support/pem-ssl-creation.htm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 05:13:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037058#M200647</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-19T05:13:12Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037059#M200660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks tarik,&lt;/P&gt;&lt;P&gt;to summarize it. i did the following.&lt;/P&gt;&lt;P&gt;1. Create CSR on both CAS &amp;amp; CAM.(in both CSR the Domain name or IP will be CAM IP Address)&lt;/P&gt;&lt;P&gt;2. Export only the CSR File (Selecting the first check box) not the key for sending to CA.&lt;/P&gt;&lt;P&gt;3. Send both the files to CA to get Certificates.&lt;/P&gt;&lt;P&gt;4. after receiving the Certs from CA, edit the Certificate file in text editor (Paste the Private Key &amp;amp; certificate of CA) and save the file. in this way there will be 3 things in this file (Certificate (generated from CSR by CA),&amp;nbsp; CA Certificate &amp;amp; Private key). Repeate the same for CAS &amp;amp; CAM.&lt;/P&gt;&lt;P&gt;5. Import the Certificate chain files created to CAS &amp;amp; CAM Respectively (means import to CAS the CAS file &amp;amp; to CAM the CAM file created)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please correct me if there is something i am missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 05:20:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037059#M200660</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-19T05:20:02Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037060#M200666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tarik,&lt;/P&gt;&lt;P&gt;i followed the steps, imported the certificates successfully, CAM connected to CAS. and CAS are in HA also.&lt;/P&gt;&lt;P&gt;now i have 2 problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. when&amp;nbsp; Agent PC logins, it goes to authentication VLAN, and after some time the NAC login window popups, the domain user id and password not working, we have to put NAC Local username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. when i login to NAC Manager. there is one message ""WARNING! Closed connections to peer [192.168.0.253] database! Please restart peer node to bring databases in sync!! """"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 09:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037060#M200666</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-19T09:06:23Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037061#M200677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tarik ??&lt;BR /&gt;Any update?? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2012 04:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037061#M200677</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-23T04:54:27Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037062#M200682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should not have to paste the private key in the ceritifcate. All you need to do is import the root ceritifcate in the CAM and CAS trusted CA store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to get the certificates installed after you import the root certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2012 06:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037062#M200682</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-23T06:01:50Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037063#M200688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tarik,&lt;BR /&gt;Now the CAS is connected to CAM and Both CAS are in HA working. but the only problem is users are not aunthenticating with AD, when the PC restarts the user goes to unauthenticated VLAN and the NAC Popups for username and Password, when i put NAC local user and password it works, but Domain user and Password is not working. in CAM Authentication screen i can see Active Directory SSO Server "Started"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2012 06:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037063#M200688</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-23T06:07:06Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037064#M200692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you generated the certificates did you use ip address (if so did you use the VIP) if hostname (did you use the hostname only).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before ADSSO was working just fine but after you updated the certs ADSSO doesnt work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can not logn with AD credentials then that is a seperate issue and you will have to add an LDAP auth provider in the CAM and configure the user login page to set the defautl auth provide as LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your unauthenticated role to make sure that there arent any DC that may have been missed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure that the certs are in the right place and the dns resolves just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2012 06:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037064#M200692</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-23T06:13:49Z</dc:date>
    </item>
    <item>
      <title>Cisco NAC, CAM &amp; CAS New certificate. agents needs to be updated</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037065#M200698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tarik,&lt;/P&gt;&lt;P&gt;Thanks again for quick reply,&lt;/P&gt;&lt;P&gt;ADSSO Was working fine before Certificates expired. i have generated certificate request using IP addresses.&lt;/P&gt;&lt;P&gt;and yes it is VIP.&lt;/P&gt;&lt;P&gt;the Auth Servers configured as "Active Directory SSO".&lt;/P&gt;&lt;P&gt;there has been nothing changed beside certificate import &amp;amp; exports.&lt;BR /&gt;what else could be the issue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2012 06:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-nac-cam-cas-new-certificate-agents-needs-to-be-updated/m-p/2037065#M200698</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-09-23T06:20:23Z</dc:date>
    </item>
  </channel>
</rss>

