<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.3 Does not connect to MS SCEP Server for BYOD Cert Request in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477549#M517925</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The process works with ISE Internal CA with Android clients. So far in our setup we have mostly Android clients. With regards to the SCEP, I have used the sscep toolset to test and verify that SCEP is working as seen below.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" height="66" src="https://community.cisco.com/legacyfs/online/fusion/115152_pastedImage_0.png" style="width: 624px; height: 66px;" width="624" /&gt;&lt;/P&gt;&lt;P&gt;The process just doesn't work when using the External SCEP Server. The RootCA and SubCA certificates have been added to ISE trusted certificates to support the External SCEP Server. Note also the SCEP server is also the SUBCA that issues the certificates.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 10 Feb 2018 13:01:44 GMT</pubDate>
    <dc:creator>ainsleye</dc:creator>
    <dc:date>2018-02-10T13:01:44Z</dc:date>
    <item>
      <title>Cisco ISE 2.3 Does not connect to MS SCEP Server for BYOD Cert Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477547#M517923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When using BYOD in a DUAL SSID setup with Microsoft Server 2012 R2 CA as a SCEP server and Android phone, the Network Setup assistant does not ask you to enter your password nor does it connect to the SCEP to relay the certificate request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2018 19:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477547#M517923</guid>
      <dc:creator>ainsleye</dc:creator>
      <dc:date>2018-02-09T19:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Does not connect to MS SCEP Server for BYOD Cert Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477548#M517924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please clarify whether it working with ISE internal CA, with other client OS's than Android, and testing SCEP connection ok.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Feb 2018 05:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477548#M517924</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-10T05:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Does not connect to MS SCEP Server for BYOD Cert Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477549#M517925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The process works with ISE Internal CA with Android clients. So far in our setup we have mostly Android clients. With regards to the SCEP, I have used the sscep toolset to test and verify that SCEP is working as seen below.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" height="66" src="https://community.cisco.com/legacyfs/online/fusion/115152_pastedImage_0.png" style="width: 624px; height: 66px;" width="624" /&gt;&lt;/P&gt;&lt;P&gt;The process just doesn't work when using the External SCEP Server. The RootCA and SubCA certificates have been added to ISE trusted certificates to support the External SCEP Server. Note also the SCEP server is also the SUBCA that issues the certificates.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Feb 2018 13:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477549#M517925</guid>
      <dc:creator>ainsleye</dc:creator>
      <dc:date>2018-02-10T13:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Does not connect to MS SCEP Server for BYOD Cert Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477550#M517926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My wireless setup is not connected to a Windows 2012R2 CA. I know for sure ISE working with Windows 2012R2 because a couple of Cisco field engineers did a Techtorial in Cisco Live before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just tried it with our existing Windows 2008R2 and my test Android device (Google Nexus 5X) got the certificate installed ok.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-02-12 at 4.59.16 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/115161_Screen Shot 2018-02-12 at 4.59.16 AM.png" style="height: 227px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screenshot_20180212-121039.png" class="jive-image image-2" height="409" src="https://community.cisco.com/legacyfs/online/fusion/115162_Screenshot_20180212-121039.png" style="height: 408.8064516129033px; width: 230px;" width="230" /&gt;&lt;/P&gt;&lt;P&gt;Below are some screenshots of my ISE configurations:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-02-12 at 6.55.31 AM.png" class="jive-image image-3" src="/legacyfs/online/fusion/115175_Screen Shot 2018-02-12 at 6.55.31 AM.png" style="height: 241px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-02-12 at 6.56.39 AM.png" class="jive-image image-4" src="/legacyfs/online/fusion/115176_Screen Shot 2018-02-12 at 6.56.39 AM.png" style="height: 486px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-02-12 at 6.58.20 AM.png" class="jive-image image-5" src="/legacyfs/online/fusion/115177_Screen Shot 2018-02-12 at 6.58.20 AM.png" style="height: 355px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still have problem to get the requests going to your MS CA, please engage Cisco TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 15:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477550#M517926</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-12T15:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Does not connect to MS SCEP Server for BYOD Cert Request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477551#M517927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the clarification as this has resolved my issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turns out that the key to getting SCEP to work is to specify the entire URL with the mscep.dll such as&lt;STRONG&gt;&lt;EM&gt; "http(s)://yourscep.yourdomain.com/certsrv/mscep/mscep.dll"&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; when creating the SCEP RA Profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 16:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-does-not-connect-to-ms-scep-server-for-byod-cert/m-p/3477551#M517927</guid>
      <dc:creator>ainsleye</dc:creator>
      <dc:date>2018-02-12T16:34:04Z</dc:date>
    </item>
  </channel>
</rss>

