<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows 7 silently refusing server certificate over dot1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-7-silently-refusing-server-certificate-over-dot1x/m-p/2850239#M36913</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have setup my controller and ISE for dot1x over wireless.&lt;/P&gt;
&lt;P&gt;I know what should be done as a best practice in terms of certificates and trusted CA...etc.&lt;/P&gt;
&lt;P&gt;However it is not do-able to verify the right certificates are on all endpoints especially that&lt;/P&gt;
&lt;P&gt;most are non-domain devices.&lt;/P&gt;
&lt;P&gt;I have no issues when MAC-OS or WIN 10 devices try to connect, they get a warning&lt;/P&gt;
&lt;P&gt;about the certificate and can choose whether to connect or not.&lt;/P&gt;
&lt;P&gt;However on windows 7 machines, the machines are SILENTLY refusing to accept the&lt;/P&gt;
&lt;P&gt;ISE certificate and failing to connect. (I can see the certificate error on ISE log)&lt;/P&gt;
&lt;P&gt;I still can't figure out when does the warning pops up or not. I need it to show up&lt;/P&gt;
&lt;P&gt;so I can ignore the warning and continue.&lt;/P&gt;
&lt;P&gt;any ideas ?&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_connect_prompt.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ibrahim&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:37:34 GMT</pubDate>
    <dc:creator>ibrahim_sms</dc:creator>
    <dc:date>2019-03-11T06:37:34Z</dc:date>
    <item>
      <title>Windows 7 silently refusing server certificate over dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-7-silently-refusing-server-certificate-over-dot1x/m-p/2850239#M36913</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have setup my controller and ISE for dot1x over wireless.&lt;/P&gt;
&lt;P&gt;I know what should be done as a best practice in terms of certificates and trusted CA...etc.&lt;/P&gt;
&lt;P&gt;However it is not do-able to verify the right certificates are on all endpoints especially that&lt;/P&gt;
&lt;P&gt;most are non-domain devices.&lt;/P&gt;
&lt;P&gt;I have no issues when MAC-OS or WIN 10 devices try to connect, they get a warning&lt;/P&gt;
&lt;P&gt;about the certificate and can choose whether to connect or not.&lt;/P&gt;
&lt;P&gt;However on windows 7 machines, the machines are SILENTLY refusing to accept the&lt;/P&gt;
&lt;P&gt;ISE certificate and failing to connect. (I can see the certificate error on ISE log)&lt;/P&gt;
&lt;P&gt;I still can't figure out when does the warning pops up or not. I need it to show up&lt;/P&gt;
&lt;P&gt;so I can ignore the warning and continue.&lt;/P&gt;
&lt;P&gt;any ideas ?&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_connect_prompt.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ibrahim&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-7-silently-refusing-server-certificate-over-dot1x/m-p/2850239#M36913</guid>
      <dc:creator>ibrahim_sms</dc:creator>
      <dc:date>2019-03-11T06:37:34Z</dc:date>
    </item>
    <item>
      <title>Hi Ibrahim-</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-7-silently-refusing-server-certificate-over-dot1x/m-p/2850240#M36914</link>
      <description>&lt;P&gt;Hi Ibrahim-&lt;/P&gt;
&lt;P&gt;A couple of questions:&lt;/P&gt;
&lt;P&gt;1. Have you confirmed that the Root CA's certificate is in the "Trusted Root Certificate" store on the client machine?&lt;/P&gt;
&lt;P&gt;2. Can you check and confirm that there aren't multiple client certificates in the local certificate store&lt;/P&gt;
&lt;P&gt;3. Can you post screenshots of how the supplicant is configured&lt;/P&gt;
&lt;P&gt;Also,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 17:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-7-silently-refusing-server-certificate-over-dot1x/m-p/2850240#M36914</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-03-30T17:23:15Z</dc:date>
    </item>
  </channel>
</rss>

