<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ERROR (SSL Routing, SSL_GET_SERVER_CERTIFICATE, Certificate verification failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3922243#M457175</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;We are using ISE version 2.3.0.298 patch 6,7 in virtual environment. We are trying to do TC-NAC from ISE GUI with AMP cloud but it show error "ERROR: while trying to connect to AMP cloud " in vendor instance while trying to connect AMP.&amp;nbsp; When we checked the log in ISE using&amp;nbsp;“show logging container tc-nac container-name &amp;lt;InstanceName&amp;gt; log-name adapter.log tail” command it show error "[Get clouds received RequestException ("bad handshake: Error([('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')],)",)].&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help us to solve this issue.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 19:09:42 GMT</pubDate>
    <dc:creator>VamsiKrishna</dc:creator>
    <dc:date>2020-02-21T19:09:42Z</dc:date>
    <item>
      <title>ERROR (SSL Routing, SSL_GET_SERVER_CERTIFICATE, Certificate verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3922243#M457175</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;We are using ISE version 2.3.0.298 patch 6,7 in virtual environment. We are trying to do TC-NAC from ISE GUI with AMP cloud but it show error "ERROR: while trying to connect to AMP cloud " in vendor instance while trying to connect AMP.&amp;nbsp; When we checked the log in ISE using&amp;nbsp;“show logging container tc-nac container-name &amp;lt;InstanceName&amp;gt; log-name adapter.log tail” command it show error "[Get clouds received RequestException ("bad handshake: Error([('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')],)",)].&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help us to solve this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3922243#M457175</guid>
      <dc:creator>VamsiKrishna</dc:creator>
      <dc:date>2020-02-21T19:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR (SSL Routing, SSL_GET_SERVER_CERTIFICATE, Certificate verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3922389#M457176</link>
      <description>&lt;P&gt;TC-NAC is a bit of a special beast.&amp;nbsp; I have not done one myself, but there is a nice write up about getting comms working between ISE and a TC-NAC third-party vendor.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may have missed the part where you have to install the CA cert chain of your TC-NAC service that ISE is connecting to (AMP in this case)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/200974-Configure-ISE-2-2-Threat-Centric-NAC-TC.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/200974-Configure-ISE-2-2-Threat-Centric-NAC-TC.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 10:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3922389#M457176</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-09-11T10:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR (SSL Routing, SSL_GET_SERVER_CERTIFICATE, Certificate verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3923258#M457177</link>
      <description>&lt;P&gt;Thank for the reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we are using Cisco AMP in our scenario. In Cisco AMP we can't generate certificate, we have a self-signed certificate in ISE.&lt;BR /&gt;is there any other way we can solve this issue ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 13:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/3923258#M457177</guid>
      <dc:creator>VamsiKrishna</dc:creator>
      <dc:date>2019-09-12T13:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR (SSL Routing, SSL_GET_SERVER_CERTIFICATE, Certificate verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/4120403#M561760</link>
      <description>&lt;P&gt;Did you ever get a resolution for this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 04:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-ssl-routing-ssl-get-server-certificate-certificate/m-p/4120403#M561760</guid>
      <dc:creator>networksumo</dc:creator>
      <dc:date>2020-07-17T04:30:21Z</dc:date>
    </item>
  </channel>
</rss>

