<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE BYOD Certificate Issue with external CA using SCEP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904351#M36737</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am running into an issue where ISE is unable to get the certificate issued from an external CA.&amp;nbsp; All ISE certificates are issued by this CA and normal authentication with and without certificates are working.&amp;nbsp; However during BYOD on-boarding, it fails during the middle of the installation.&amp;nbsp; I looked through the debugs on the client side and ISE side.&amp;nbsp; I can see some errors on the ISE side.&amp;nbsp; However, I am not able to understand what the error message means.&lt;/P&gt;
&lt;P&gt;I suspect the issue is with the external CA, because when I connected the same ISE set up to another external CA, I could successfully get a certificate downloaded to the client.&amp;nbsp; However this did not help my situation because that is not a trusted CA in my ISE Trusted store.&amp;nbsp; I am copying the error section of both client and ISE debugs. The client is a Windows 7 laptop.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Appreciate if some information can be shed on the error message.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/topology_32.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN dir="ltr"&gt;&lt;FONT color="black" size="3" face="Calibri,Arial,Helvetica,sans-serif"&gt;&lt;SPAN style="font-size: 12pt; background-color: white;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:39:40 GMT</pubDate>
    <dc:creator>xovercable</dc:creator>
    <dc:date>2019-03-11T06:39:40Z</dc:date>
    <item>
      <title>ISE BYOD Certificate Issue with external CA using SCEP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904351#M36737</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am running into an issue where ISE is unable to get the certificate issued from an external CA.&amp;nbsp; All ISE certificates are issued by this CA and normal authentication with and without certificates are working.&amp;nbsp; However during BYOD on-boarding, it fails during the middle of the installation.&amp;nbsp; I looked through the debugs on the client side and ISE side.&amp;nbsp; I can see some errors on the ISE side.&amp;nbsp; However, I am not able to understand what the error message means.&lt;/P&gt;
&lt;P&gt;I suspect the issue is with the external CA, because when I connected the same ISE set up to another external CA, I could successfully get a certificate downloaded to the client.&amp;nbsp; However this did not help my situation because that is not a trusted CA in my ISE Trusted store.&amp;nbsp; I am copying the error section of both client and ISE debugs. The client is a Windows 7 laptop.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Appreciate if some information can be shed on the error message.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/topology_32.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN dir="ltr"&gt;&lt;FONT color="black" size="3" face="Calibri,Arial,Helvetica,sans-serif"&gt;&lt;SPAN style="font-size: 12pt; background-color: white;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904351#M36737</guid>
      <dc:creator>xovercable</dc:creator>
      <dc:date>2019-03-11T06:39:40Z</dc:date>
    </item>
    <item>
      <title>Post did not allow me to add</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904352#M36740</link>
      <description>&lt;P&gt;Post did not allow me to add debugs complaining of invalid characters.&amp;nbsp; Giving it a show as a reply:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$&lt;BR /&gt;&lt;BR /&gt;Error on ISE debugs from ise-psc.log file&lt;BR /&gt;&lt;BR /&gt;$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://127.0.0.1:9444/caservice/scep" target="_blank"&gt;http://127.0.0.1:9444/caservice/scep&lt;/A&gt;[live,7675,0,0,5]&lt;BR /&gt;2016-04-05 23:19:32,433 DEBUG&amp;nbsp; [DefaultQuartzScheduler_Worker-2][] com.cisco.cpm.scep.ScepCertRequestProcessor -:::::- SCEP job scheduler statistics [pool size=0, active=0]&lt;BR /&gt;2016-04-05 23:19:32,663 DEBUG&amp;nbsp; [portal-http-service49][] com.cisco.cpm.scep.CertRequestInfo -:::::- Found challenge password with cert template ID.&lt;BR /&gt;2016-04-05 23:19:32,663 DEBUG&amp;nbsp; [portal-http-service49][] cisco.cpm.provisioning.cert.CertProvisioningFactory -:::::- Found incoming certifcate request for external CA. Not touching Cert Request counter.&lt;BR /&gt;2016-04-05 23:19:32,671 INFO&amp;nbsp;&amp;nbsp; [portal-http-service49][] com.cisco.cpm.scep.ScepCertRequestProcessor -:::::- About to forward certificate request C=US,ST=State,L=City,O=Company name,OU=Example unit,CN=cuser4 with transaction id&amp;nbsp; &amp;gt;|ï¿½Qz&amp;#16;&amp;#1;6ï¿½&amp;#16;8ï¿½ï¿½ ï¿½ ï¿½ ^ï¿½ï¿½ï¿½ï¿½ï¿½Ax&amp;#23;ï¿½&amp;nbsp; to server &lt;A href="http://10.1.103.102/certsrv/mscep" target="_blank"&gt;http://10.1.103.102/certsrv/mscep&lt;/A&gt;&lt;BR /&gt;2016-04-05 23:19:32,675 DEBUG&amp;nbsp; [portal-http-service49][] org.jscep.message.PkiMessageEncoder -:::::- Encoding message: org.jscep.message.PkcsReq@5902ef2f[transId=61977c80534d2b5b5130d341d20322a7f907708a,messageType=PKCS_REQ,senderNonce=Nonce [403814a5b93c21140f96a757bb33e0a2],messageData=org.bouncycastle.pkcs.PKCS10CertificationRequest@43bdbe49]&lt;BR /&gt;2016-04-05 23:19:32,675 DEBUG&amp;nbsp; [portal-http-service49][] org.jscep.message.PkcsPkiEnvelopeEncoder -:::::- Encrypting session key using key belonging to [issuer=CN=CTEK Issuing CA, DC=CTEK, DC=COM; serial=122709060007106850062357]&lt;BR /&gt;2016-04-05 23:19:32,676 DEBUG&amp;nbsp; [portal-http-service49][] org.jscep.message.PkiMessageEncoder -:::::- Signing message using key belonging to [issuer=CN=CTEK Issuing CA, DC=CTEK, DC=COM; serial=106579447778026949967889]&lt;BR /&gt;2016-04-05 23:19:32,678 DEBUG&amp;nbsp; [portal-http-service49][] org.jscep.message.PkiMessageEncoder -:::::- Signing org.bouncycastle.cms.CMSProcessableByteArray@6071fb21 content&lt;BR /&gt;2016-04-05 23:19:32,704 WARN&amp;nbsp;&amp;nbsp; [New I/O client worker #2-1][] org.jscep.message.PkiMessageDecoder -:::::- Unable to verify message because the signedData contained no certificates.&lt;BR /&gt;2016-04-05 23:19:32,705 DEBUG&amp;nbsp; [New I/O client worker #2-1][] org.jscep.message.PkiMessageDecoder -:::::- Decoded to: org.jscep.message.CertRep@246de576[recipientNonce=Nonce [403814a5b93c21140f96a757bb33e0a2],pkiStatus=FAILURE,failInfo=badMessageCheck,transId=61977c80534d2b5b5130d341d20322a7f907708a,messageType=CERT_REP,senderNonce=Nonce [fbc110cb906ef0419e1b227c6e5ff671],messageData=&amp;lt;null&amp;gt;]&lt;BR /&gt;2016-04-05 23:19:34,697 DEBUG&amp;nbsp; [portal-http-service46][] com.cisco.cpm.scep.ScepCertRequestProcessor -:::::- Polling C=US,ST=State,L=City,O=Company name,OU=Example unit,CN=cuser4 for certificate request&amp;nbsp; &amp;gt;|ï¿½Qz&amp;#16;&amp;#1;6ï¿½&amp;#16;8ï¿½ï¿½ ï¿½ ï¿½ ^ï¿½ï¿½ï¿½ï¿½ï¿½Ax&amp;#23;ï¿½&amp;nbsp; with id {}&lt;BR /&gt;2016-04-05 23:19:34,699 WARN&amp;nbsp;&amp;nbsp; [portal-http-service46][] com.cisco.cpm.scep.ScepCertRequestProcessor -:::::- Certificate request failed for C=US,ST=State,L=City,O=Company name,OU=Example unit,CN=cuser4 due to: badMessageCheck&lt;BR /&gt;2016-04-05 23:19:34,699 WARN&amp;nbsp;&amp;nbsp; [portal-http-service46][] com.cisco.cpm.scep.ScepCertRequestProcessor -:::::- Certificate request failed for C=US,ST=State,L=City,O=Company name,OU=Example unit,CN=cuser4 due to: badMessageCheck&lt;BR /&gt;2016-04-05 23:19:34,700 DEBUG&amp;nbsp; [portal-http-service46][] com.cisco.cpm.scep.ScepCertRequestProcessor -:::::- Found incoming certifcate request for external CA. Not touching Cert Request counter.&lt;BR /&gt;2016-04-05 23:19:34,710 DEBUG&amp;nbsp; [portal-http-service46][] com.cisco.cpm.scep.CertRequestInfo -:::::- Found challenge password with cert template ID.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$&lt;BR /&gt;&lt;BR /&gt;Output of client side log: spwProfileLog&lt;BR /&gt;&lt;BR /&gt;$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] Logging started&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] SPW Version: 1.0.0.46&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] System locale is [en]&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] Loading messages for english...&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] Initializing profile&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] SPW is running as High integrity Process - 12288&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] GetProfilePath: searched path = C:\Users\Owner\AppData\Local\Temp\ for file name = spwProfile.xml result: 0&lt;BR /&gt;[Tue Apr 05 19:03:20 2016] GetProfilePath: searched path = C:\Users\Owner\AppData\Local\Temp\Low for file name = spwProfile.xml result: 0&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Profile xml not found Downloading profile configuration...&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Downloading profile configuration...&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Discovering ISE using default gateway&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Identifying wired and wireless network interfaces, total active interfaces: 1&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Network interface - mac:58-94-6B-FB-FD-44, name: Wireless Network Connection 3, type: wireless&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Identified default gateway: 10.1.61.254&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] Identified default gateway: 10.1.61.254, mac address: 58-94-6B-FB-FD-44&lt;BR /&gt;[Tue Apr 05 19:03:23 2016] DiscoverISE - start&lt;BR /&gt;[Tue Apr 05 19:03:35 2016] Discovered ISE - : [ISE-PUB.ctek.com, sessionId: 0a01c907000000105704522d]&lt;BR /&gt;&lt;BR /&gt;[Tue Apr 05 19:03:35 2016] DiscoverISE - end&lt;BR /&gt;[Tue Apr 05 19:03:35 2016] Successfully Discovered ISE: ISE-PUB.ctek.com, session id: 0a01c907000000105704522d, macAddress: 58-94-6B-FB-FD-44&lt;BR /&gt;[Tue Apr 05 19:03:35 2016] GetProfile - start&lt;BR /&gt;[Tue Apr 05 19:03:35 2016] Warning - [HTTPConnection:RetrySendRequest] InternetOpen() failed with code: [12045]&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] GetProfile - end&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] Successfully retrieved profile xml&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] using V2 xml version&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] parsing wireless connection setting&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] Certificate template: [keysize:2048, subject:OU=Example unit,O=Company name,L=City,ST=State,C=US, SAN:MAC]&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] set ChallengePwd&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] Starting parsing proxy configuration&lt;BR /&gt;[Tue Apr 05 19:03:39 2016] ProxySettings key was not found in the configuration xml&lt;BR /&gt;[Tue Apr 05 19:03:40 2016] found redirect URL:&lt;BR /&gt;[Tue Apr 05 19:03:40 2016] Identifying wired and wireless network interfaces, total active interfaces: 1&lt;BR /&gt;[Tue Apr 05 19:03:40 2016] Network interface - mac:58-94-6B-FB-FD-44, name: Wireless Network Connection 3, type: wireless&lt;BR /&gt;[Tue Apr 05 19:03:40 2016] Wireless interface [Wireless Network Connection 3] will be configured...&lt;BR /&gt;[Tue Apr 05 19:03:40 2016] Host - [ name:RAJPC, mac addresses:58-94-6B-FB-FD-44;5C-26-0A-42-69-1F]&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] ApplyProfile - Start...&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] User Id: cuser4, sessionid: 0a01c907000000105704522d, Mac: 58-94-6B-FB-FD-44, profile: CTEK_NSP&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] number of wireless connections to configure: 1&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] applying certificate for ssid [CORPORATE]&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] ApplyCert - Start...&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] using ChallengePwd&lt;BR /&gt;[Tue Apr 05 19:03:41 2016] creating certificate with subject = cuser4 and subjectSuffix = OU=Example unit,O=Company name,L=City,ST=State,C=US&lt;BR /&gt;[Tue Apr 05 19:03:42 2016] Installed [CTEK Issuing CA, hash: ec 9b 4f bd cb d8 fe ad&amp;nbsp; 4a d9 2d 97 29 c8 75 fe&lt;BR /&gt;&lt;BR /&gt;03 3e ce 55&lt;BR /&gt;&lt;BR /&gt;] as intermediateCA&lt;BR /&gt;[Tue Apr 05 19:03:45 2016] Installed [CTEK Corporate Root CA, hash: 44 56 cd de 8a f6 b9 95&amp;nbsp; c8 42 ee 09 99 29 00 d9&lt;BR /&gt;&lt;BR /&gt;69 ec b5 1a&lt;BR /&gt;&lt;BR /&gt;] as rootCA&lt;BR /&gt;[Tue Apr 05 19:03:45 2016] Installed CA cert for authMode machineOrUser - Success&lt;BR /&gt;[Tue Apr 05 19:03:45 2016] HttpWrapper::SendScepRequest - Retrying: [1] time, after: [2] secs , Error: [0], msg: [ Pending]&lt;BR /&gt;[Tue Apr 05 19:03:47 2016] HttpWrapper::SendScepRequest - Retrying: [2] time, after: [2] secs , Error: [0], msg: [ Error]&lt;BR /&gt;[Tue Apr 05 19:03:49 2016] HttpWrapper::SendScepRequest - Retrying: [3] time, after: [2] secs , Error: [0], msg: [ Pending]&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] Failed to get certificate from server - Error: [0]&lt;BR /&gt;&amp;nbsp;HTTP Response: [HTTP/1.1 200 OK&lt;BR /&gt;&lt;BR /&gt;Trans-Status: Error&lt;BR /&gt;&lt;BR /&gt;Content-Length: 0&lt;BR /&gt;&lt;BR /&gt;Date: Wed, 06 Apr 2016 00:03:49 GMT&lt;BR /&gt;&lt;BR /&gt;Server:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;]&lt;BR /&gt;&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ScepWrapper::InstallCert start&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ScepWrapper::InstallCert: Reading scep response file&amp;nbsp; [C:\Users\Owner\AppData\Local\Temp\response.cer].&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ScepWrapper::InstallCert CreateFile failed&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ScepWrapper::InstallCert end&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] Failed to install identity certificate. Error code: [183]. Check the certificate template on the CA server and the certificate issued for the client on the CA server. Certificate should be for the purpose of Client Authentication.&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ApplyCert - End...&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ApplyCert failed ....&amp;nbsp; 0ca8f1b6-500d-560b-e053-75189a0ab0d1&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] Configuring SSID proxies ...&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] Failed to configure the device.&lt;BR /&gt;[Tue Apr 05 19:03:51 2016] ApplyProfile - End..&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 05:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904352#M36740</guid>
      <dc:creator>xovercable</dc:creator>
      <dc:date>2016-04-11T05:06:26Z</dc:date>
    </item>
    <item>
      <title>Hi xovercable,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904353#M36743</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN style="color: #000000;"&gt;&lt;A href="https://supportforums.cisco.com/users/xovercable" title="View user profile." class="username" lang="" about="/users/xovercable" typeof="sioc:UserAccount" property="foaf:name" datatype="" style="color: #000000;"&gt;xovercable&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;i am facing the same issue by using &amp;nbsp;ISE internal CA, please let us know if the above issue has been resolved, if yes, how?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Thanks in Advance&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Vikas&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 06:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904353#M36743</guid>
      <dc:creator>maharanavikas3621</dc:creator>
      <dc:date>2016-08-17T06:02:23Z</dc:date>
    </item>
    <item>
      <title>I can't remember exactly the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904354#M36746</link>
      <description>&lt;P&gt;I can't remember exactly the reason because we ran into several issues :-). &amp;nbsp;But I believe the following was the reason. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Exchange Enrollment Agent Certificate that got created was invalid due to the sequence in which it was created. &amp;nbsp;So I had to delete the Exchange Enrollment Agent Certificate and the system will recreate a new one when you restart the CA server.&lt;/P&gt;
&lt;P&gt;But the cause for your problem may be different. &amp;nbsp;Did you verify the NDES itself is working by going to the CA server URL?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;http://&amp;lt;FQDN of NDES Server&amp;gt;/certsrv/mscep/mscep.dll&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 16:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/2904354#M36746</guid>
      <dc:creator>xovercable</dc:creator>
      <dc:date>2016-08-18T16:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: I can't remember exactly the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/3841574#M36748</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Check the certificate template on the CA server and the certificate issued for the client on the CA server. Certificate should be for the purpose of Client Authentication.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 08:34:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-issue-with-external-ca-using-scep/m-p/3841574#M36748</guid>
      <dc:creator>mumbai.support</dc:creator>
      <dc:date>2019-04-19T08:34:42Z</dc:date>
    </item>
  </channel>
</rss>

