<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ise cert in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000218#M245409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind regardless of a public or private certificate most clients will always prompt the user to accept the radius server warning on all initial 802.1x connections. The only device I have seen not present this prompt is the android.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The supplicant will always warn the end user that the identity for network authentication will be passed on to a radius server, the only way to hide this message by choosing to keep the validate server certificate option would be to use a group policy from GPMC on your microsoft environment where the identity is automatically set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Jan 2014 16:01:00 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2014-01-06T16:01:00Z</dc:date>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000207#M245366</link>
      <description>&lt;P&gt;When I generate a cert and use THAWT tiral version to try out the cert, the request as I copy - paste it says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The CSR must include an Organization Name.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using ISE 1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://ssl-certificate-center.thawte.com/process/retail/trial_product_selector;jsessionid=05DB2EB1E2E8FD67154B46999D600182?uid=f7293ccbbdb28c74c6a817943e96b3bd&amp;amp;locale=THAWTE_US" target="_blank"&gt;https://ssl-certificate-center.thawte.com/process/retail/trial_product_selector;jsessionid=05DB2EB1E2E8FD67154B46999D600182?uid=f7293ccbbdb28c74c6a817943e96b3bd&amp;amp;locale=THAWTE_US&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000207#M245366</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2019-03-11T02:21:29Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000208#M245369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please use this guide to generate the csr, i could not view the link that you posted above. Do you have a screenshot of the error, also a screenshot of the csr details?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_man_cert.html#wp1077292"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_man_cert.html#wp1077292&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 20:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000208#M245369</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-30T20:30:19Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000209#M245373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was actually reading it before you posted, i am thankful for your help and I apologize for my ignorance of not reading it before I asked ( that's not me at all lol)&lt;/P&gt;&lt;P&gt;yes I have generated a self signing request and they emailed me two files:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thawte Test CA Root certificate:&lt;/P&gt;&lt;P&gt;Thawte Trial Secure Server Intermediate CA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;they emailed these two files, actually it's a separate text.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 20:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000209#M245373</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-07-30T20:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000210#M245377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am actually trying to set it up with trial cert.&lt;/P&gt;&lt;P&gt;google: thawte trial ssl cert&lt;/P&gt;&lt;P&gt;they offer 21 day trial but I am going to digg a bit more to see whats goin on, can't seem to make it work.&lt;/P&gt;&lt;P&gt;if you have time it'd be nice if you could install it and post the solution.&lt;/P&gt;&lt;P&gt;If i figure it out i'll post the solution.&lt;/P&gt;&lt;P&gt;thanks alot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 20:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000210#M245377</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-07-30T20:40:44Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000211#M245379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not a problem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what you will do is save the files according. One file you can save as certificate.cer, and the other root certificate as root.cer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will upload the root certificate first in the CA store and then upload the certificate.cer in the local certificate store. Let me know if you need help with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 21:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000211#M245379</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-30T21:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000212#M245381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your help once again, I think i will have to digg in.&lt;/P&gt;&lt;P&gt;Anyway as I was readying the documentation for CISCO ISE on page &lt;STRONG&gt;382&lt;/STRONG&gt; of document: &lt;STRONG&gt;ise_ug1.1.1.pdf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bolded word down there should be Certificate Store maybe?&lt;/P&gt;&lt;P&gt;Not sure if it's a typo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" Adding a Certificate Authority Certificate&lt;/P&gt;&lt;P&gt;Note Before you add a certificate authority certificate, ensure that the certificate authority certificate resides&lt;/P&gt;&lt;P&gt;on the file system that is running the client browser.&lt;/P&gt;&lt;P&gt;Prerequisite:&lt;/P&gt;&lt;P&gt;Every ISE administrator account is assigned one or more administrative roles. To perform the operations&lt;/P&gt;&lt;P&gt;described in the following procedure, you must have the Super Admin or System Admin role assigned.&lt;/P&gt;&lt;P&gt;See Cisco ISE Admin Group Roles and Responsibilities for more information on the various&lt;/P&gt;&lt;P&gt;administrative roles and the privileges associated with each of them.&lt;/P&gt;&lt;P&gt;To add a certificate authority certificate, complete the following steps:&lt;/P&gt;&lt;P&gt;Step 1 Choose Administration &amp;gt; System &amp;gt; Certificates.&lt;/P&gt;&lt;P&gt;Step 2 From the Certificate Operations navigation pane on the left, &lt;STRONG&gt;click Certificate Authority Certificates&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The Certificate Authority Certificates page appears.&lt;/P&gt;&lt;P&gt;Step 3 Click Add.&lt;/P&gt;&lt;P&gt;The Import a new Trusted CA (Certificate Authority) Certificate page appears as shown in Figure 13-10 """&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 21:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000212#M245381</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-07-30T21:26:16Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000213#M245384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct for the root certificate, my wording wasnt exact but that is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For the local certificate you can use these steps - &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_man_cert.html#wp1103485"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_man_cert.html#wp1103485&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 21:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000213#M245384</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-30T21:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000214#M245385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I generate a cert and use THAWT tiral version,I received the certificate as trial SSL certificate ,Trial Secure Server Intermediate CA and Test CA Root certificate which is totally three my problem now I am very new in certificate concept and I don’t know how to move forward:&amp;nbsp; &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shall I do construct it as following details :&lt;/P&gt;&lt;P&gt;{Trial SSL certificate, followed by trial intermediate and followed by trial test root} and then save it in one file with .PEM extension&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or I have save each file individually with .pem extension.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally how I import this certificate to my ISE 1.2, which one should be to import to local certificates and which one to Certificate Store ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 05:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000214#M245385</guid>
      <dc:creator>ITA7DMIN99</dc:creator>
      <dc:date>2014-01-06T05:07:53Z</dc:date>
    </item>
    <item>
      <title>Re:ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000215#M245388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Method one is correct. You will need to bind and not import if you generated the certificate signing request on the ise server.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 06:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000215#M245388</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2014-01-06T06:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000216#M245394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should i do any things in Certificate Store?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 06:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000216#M245394</guid>
      <dc:creator>ITA7DMIN99</dc:creator>
      <dc:date>2014-01-06T06:55:19Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000217#M245401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I export that local certificate of the ISE and save it in the trusted store of the Client, but still receive the error “12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate”.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i dont want to uncheck the validate server certificate option from the client network profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please advise ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 15:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000217#M245401</guid>
      <dc:creator>ITA7DMIN99</dc:creator>
      <dc:date>2014-01-06T15:26:18Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000218#M245409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind regardless of a public or private certificate most clients will always prompt the user to accept the radius server warning on all initial 802.1x connections. The only device I have seen not present this prompt is the android.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The supplicant will always warn the end user that the identity for network authentication will be passed on to a radius server, the only way to hide this message by choosing to keep the validate server certificate option would be to use a group policy from GPMC on your microsoft environment where the identity is automatically set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 16:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000218#M245409</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2014-01-06T16:01:00Z</dc:date>
    </item>
    <item>
      <title>ise cert</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000219#M245416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;Still error shown “12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate”. Maybe i need to delete the a default, self-signed certificate after bind the new one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 06:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cert/m-p/2000219#M245416</guid>
      <dc:creator>ITA7DMIN99</dc:creator>
      <dc:date>2014-01-07T06:02:16Z</dc:date>
    </item>
  </channel>
</rss>

