<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE - Guest portal Cert query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847108#M204318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;If you got an update related to Subject Alternate Names could you post the information? I'm also interested in this functionality to fix the issue so that we can give the appliance multiple certificates with other domain names. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Regards,&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Sander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jun 2012 09:50:43 GMT</pubDate>
    <dc:creator>S M85</dc:creator>
    <dc:date>2012-06-18T09:50:43Z</dc:date>
    <item>
      <title>Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847103#M204313</link>
      <description>&lt;P&gt;I have brief question regarding the Cisco ISE appliance and guest portal cert’s.&lt;/P&gt;&lt;P&gt;Ideally in my customer environment we want to hide our infrastructure hence the below...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Summary&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Guest Web authentication is working through the controller and then passed onto the ISE server&lt;/LI&gt;&lt;LI&gt;The business would like to remove the ‘untrusted certification error’ that users are getting when they login&lt;/LI&gt;&lt;LI&gt;On the controller I can set the ‘FQDN’ via the virtual interface and apply/obtain a public cert for that name.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Challenge&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Currently the ‘hostname’ of the ISE&amp;nbsp; server is ‘prod-net-ise01’&amp;nbsp; (that is the mgmt name of the device)&lt;/LI&gt;&lt;LI&gt;I can only seem to generate a cert for the ‘hostname’ of the device and that will not hide what it is..&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to apply a HTTP/HTTPS public cert on the ISE server with a FQDN that does not match the hostname?&lt;/P&gt;&lt;P&gt;i.e. similar to the way that the controller does it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not then what would the process be to change the ‘hostname’ of the ISE device, Can that only be done via the CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any help or pointing me in the right direction.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847103#M204313</guid>
      <dc:creator>DanWeinstock909</dc:creator>
      <dc:date>2019-03-11T01:43:06Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847104#M204314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just tried to use a wildcard certificate, and received the error message that the "Management certificate must contain host FQDN in CN component of Subject field."&amp;nbsp; This is a HUGE issue.&amp;nbsp; Currently, I can use wildcard certs on the WLCs without an issue.&amp;nbsp; And, I can import a separate one for web logins from the one used for management.&amp;nbsp; ISE really needs to have the ability to import a separate, non-"Management" certificate just used for "Guest" logins.&amp;nbsp; Not sure if that is part of the blueprint for ISE 1.2, but it needs to be.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 13:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847104#M204314</guid>
      <dc:creator>JASON BOYERS</dc:creator>
      <dc:date>2012-05-23T13:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847105#M204315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am meeting a similar issue, which is for sponsor portal, not for guess portal, because we put guest portal on the WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ISE 1.1, an option for sponsor portal FQDN is found in the general options. However, it seems not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've opened a TAC case, Cisco engineer said he turned to developer for further checking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully it can be addressed in next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 08:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847105#M204315</guid>
      <dc:creator>surzn</dc:creator>
      <dc:date>2012-06-03T08:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847106#M204316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's confirmed not supported in current version sadly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have to change the host name ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2012 04:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847106#M204316</guid>
      <dc:creator>surzn</dc:creator>
      <dc:date>2012-06-17T04:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847107#M204317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This last week at CiscoLive, I heard that there may be a workaround using Subject Alternate Names in the certificate.&amp;nbsp; Now, this is not something that can be done using the CSR from ISE.&amp;nbsp; I'm waiting for some documentation on the process, but I aat least have a little bit of hope.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2012 13:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847107#M204317</guid>
      <dc:creator>JASON BOYERS</dc:creator>
      <dc:date>2012-06-17T13:14:14Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847108#M204318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;If you got an update related to Subject Alternate Names could you post the information? I'm also interested in this functionality to fix the issue so that we can give the appliance multiple certificates with other domain names. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Regards,&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Sander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 09:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847108#M204318</guid>
      <dc:creator>S M85</dc:creator>
      <dc:date>2012-06-18T09:50:43Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847109#M204319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; This question has been answered here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps11640/products_tech_note09186a0080bd0953.shtml"&gt;http://www.cisco.com/en/US/products/ps11640/products_tech_note09186a0080bd0953.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2013 22:25:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847109#M204319</guid>
      <dc:creator>aman.diwakar</dc:creator>
      <dc:date>2013-03-05T22:25:35Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847110#M204320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't believe there's an easy way around this currently. The URL for the PSN is created dynamically and is always the real hostname of the PSN node. If you have the luxury of multiple appliances (or VMWare partitions) available, then you can have a couple of your PSN's dedicated for guest (and maybe sponsor) access. These can then be on separate (more covert) nostnames and even on separate domain so that guest users don't see your internal domain. For split domains you will need at least 1.1.1 patch 4 (unless you can use a DNS bodge which we have tested).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 11:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847110#M204320</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2013-03-06T11:11:41Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE - Guest portal Cert query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847111#M204321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Aman and Bikspace,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the record: i have the documentation and the SAN field isn't resolving the issue for multple domain names. Altought you can specify other hostnames, it is still in the same domain suffix. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like Bikespace mention: the solution for the problem can be resolved in this way. &lt;/P&gt;&lt;P&gt;Setup a Deployment for two ISE nodes. Take up a VM and built this for DMZ purpose. You can install a PSN with an other DNS suffix. As long as these domain names are resolvable in the DNS deployment it will work. I've build this and it works with 1.1.2 patch 2. I thought this would be a problem for the AD agent on the PSN with an other DNS suffix than the real Domain Controller in the Active Directory domain, but this isn't; it will work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Extra tip: you can't register a 'real' certificate on a fake DNS name. So .local and .lan should be denied by your CA. So this solution above is the only solution for now. Also the problem lies in ISE. You can't install another certificate that is different than the hostname+suffix of the PSN node. I prefer that Cisco solve this issue like the behavior in Cisco ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00809fcf91.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00809fcf91.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or on the same interface with differents ports! it shoudn't be so hard for Cisco to implement this. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 08:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-guest-portal-cert-query/m-p/1847111#M204321</guid>
      <dc:creator>S M85</dc:creator>
      <dc:date>2013-03-07T08:45:27Z</dc:date>
    </item>
  </channel>
</rss>

