<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480735#M518807</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Therefore, it is expected. If you want to validate the server identity, then please ensure the root CA certificate is in the trusted root CA store on the client, showing up as one of the authorities in the properties screen, and selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The screenshot from a Windows-7 client below shows "root-CA" selected, as that is the one used to issue the ISE certificates in our lab.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-01-08 at 9.58.52 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/114463_Screen Shot 2018-01-08 at 9.58.52 AM.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jan 2018 18:00:34 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-01-08T18:00:34Z</dc:date>
    <item>
      <title>CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480730#M518795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE node: 2 node deployment&lt;/P&gt;&lt;P&gt;Version: 2.2 patch3&lt;/P&gt;&lt;P&gt;Certificate (Entrust):&amp;nbsp; Here the certificate view on ISE system certificat item&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114449_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;It's a wilcard SAN certificate:&lt;/P&gt;&lt;P&gt;exemple&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CN: exemple.domain.com&lt;/P&gt;&lt;P&gt;SAN:&lt;/P&gt;&lt;P&gt;exemple.domain.com (DNS)&lt;/P&gt;&lt;P&gt;*.domain.com (DNS)&lt;/P&gt;&lt;P&gt;*.anotherdomain.com (DNS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Sponsor portal, Guest POrtal, admin Portal use the certificate without any issue (SSL/TLS)&lt;/P&gt;&lt;P&gt;EAP auth. on Android endpoints is working ok.&lt;/P&gt;&lt;P&gt;Windows 8.1 PCs are not trusting the certificate.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WHY ? HELP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another détails:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows PC error from client side&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/114450_pastedImage_2.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;The error detail from the Windows log store (Eap host)&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/114451_pastedImage_3.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/114452_pastedImage_4.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;I've verified the points of the follow link:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Century Gothic','sans-serif'; font-size: 8pt; mso-bidi-font-family: Univers-Black; mso-bidi-font-weight: bold;"&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200295-Install-a-3rd-party-CA-certificate-in-IS.html#anc1"&gt;&lt;SPAN style="color: #000080; text-decoration: underline;"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200295-Install-a-3rd-party-CA-certificate-in-IS.html#anc1&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1- Verify ISE is passing the full certificate chain during the SSL handshake process. ok&lt;/P&gt;&lt;P&gt;2-Open each certificate (server, intermediate and root) and verify chain of trust by matching the Subject Key Identifier (SKI) of each certificate to the Authority Key Identifier (AKI) of the next certificate in the chain. OK&lt;/P&gt;&lt;P&gt;3-the next step is to verify that the Root and(or) Intermediate certificates are in the client Local Trust Store. OK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jan 2018 21:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480730#M518795</guid>
      <dc:creator>Equipe Telecommunications</dc:creator>
      <dc:date>2018-01-05T21:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480731#M518797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this PEAP/MSCHAPv2? Or, is it EAP-TLS? Is the connection failure after clicking on "Continue"? Have you tried other Windows client O/S, such as Windows 7 or Windows 10?&lt;/P&gt;&lt;P&gt;Sorry, I can't read French much, so can't tell what the windows errors are.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jan 2018 23:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480731#M518797</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-05T23:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480732#M518800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a client machine i think this is normal . How a create a certificate profile ?&lt;/P&gt;&lt;P&gt;This is simple example.&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114457_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 07:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480732#M518800</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-01-08T07:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480733#M518803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's PEAP/MSCHAPv2. After clicking on continue the connexion works ok.&lt;/P&gt;&lt;P&gt;The message in french is the answer of the Windows 802.1x supplicant when It's not able to trust the certificate following the notification option configured on supplicant. Here below, the default option on Windows 8.1 Under (Notifications avant la connexion: Informer l'utilisateur si le nom du server.....). In brief, the supplicant has to notify the client to trust or not the connexion in case of server certificate error. This is a confirmation of my certificate issue. If I take off the server identity validation item on supplicant, the connexion takes place without error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114467_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 14:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480733#M518803</guid>
      <dc:creator>Equipe Telecommunications</dc:creator>
      <dc:date>2018-01-08T14:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480734#M518805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm using a user authentication PEAP/MSCHAPv2 (non machine authentication).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 14:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480734#M518805</guid>
      <dc:creator>Equipe Telecommunications</dc:creator>
      <dc:date>2018-01-08T14:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE ERROR ON WINDOWS 8.1 PC CONCERNING EAP AUTH</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480735#M518807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Therefore, it is expected. If you want to validate the server identity, then please ensure the root CA certificate is in the trusted root CA store on the client, showing up as one of the authorities in the properties screen, and selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The screenshot from a Windows-7 client below shows "root-CA" selected, as that is the one used to issue the ISE certificates in our lab.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-01-08 at 9.58.52 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/114463_Screen Shot 2018-01-08 at 9.58.52 AM.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 18:00:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-error-on-windows-8-1-pc-concerning-eap-auth/m-p/3480735#M518807</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-08T18:00:34Z</dc:date>
    </item>
  </channel>
</rss>

