<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.2 pxGrid - issue with CSR signing by CA server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587077#M519011</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool that makes sense thanks! It worked fine in my lab on a standalone CA as you said, whereas the customer here has a 2-tier setup…&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas Lenzenhofer&lt;/P&gt;&lt;P&gt;Network Security Consulting Engineer&lt;/P&gt;&lt;P&gt;Advanced Services / Security IDT&lt;/P&gt;&lt;P&gt;Cisco Systems APJC/Australia&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Dec 2017 05:19:04 GMT</pubDate>
    <dc:creator>tlenzenh</dc:creator>
    <dc:date>2017-12-19T05:19:04Z</dc:date>
    <item>
      <title>ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587070#M519004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;Hi Team, &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;Not sure what the best alias is for this since its more related to Microsoft CA server than ISE or Stealthwatch but maybe someone from the team can help me out here…&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;I’m at my customer site trying to get the ISE v2.2 integration with Stealthwatch working. The customer has an internal CA server and we followed the attached guide (see page 10 onwards) for the CA pxGrid certificate template config. This worked perfectly in my lab, however at the customer site we are getting an error when we try to sign the ISE node’s Certificate Signing request for pxGrid usage based on that CA server pxGrid certificate template.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;The error we are getting is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;STRONG style="font-size: 14pt; font-family: Calibri;"&gt;Certificate Request Denied&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;Your certificate request was denied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;Your Request Id is 53. The disposition message is "Error Constructing or Publishing Certificate Invalid Issuance Policies: 2.5.29.32.0".&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;Contact your administrator for further information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;&lt;SPAN style="font-size: 14pt; font-family: Calibri;"&gt;We did some search on google as to what the potential issue could be but can’t work out whats wrong with the template.&lt;BR /&gt;Anyone got some suggestions?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;Thanks in advance&lt;/P&gt;&lt;P style="font-size: 10pt; font-family: Arial; color: #000000;"&gt;Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 04:19:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587070#M519004</guid>
      <dc:creator>tlenzenh</dc:creator>
      <dc:date>2017-12-19T04:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587071#M519005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the link to the ISE with Stealthwatch Integration that we used as a guide for the CA Server template config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-71929"&gt;https://communities.cisco.com/docs/DOC-71929&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 04:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587071#M519005</guid>
      <dc:creator>tlenzenh</dc:creator>
      <dc:date>2017-12-19T04:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587072#M519006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems like Microsoft CA is used and we've seen problems with "all insurance policy" in the cert template before. I would suggest you to try Garjendran's reply on 2013-Sept-03 to &lt;A href="https://supportforums.cisco.com/t5/aaa-identity-and-nac/ise-on-boarding-process/td-p/2272911" title="https://supportforums.cisco.com/t5/aaa-identity-and-nac/ise-on-boarding-process/td-p/2272911"&gt;ISE On-Boarding process - Cisco Support Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best to consult Microsoft. An old note I had showed it possible to disable the check at the CA side:&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: Helvetica; font-size: 12px; margin-left: 30pt;"&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Run the following command at the CA and restart the CA service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;&lt;SPAN style="font-family: Monaco, serif;"&gt;certutil –setreg CA\CRLFlags +CRLF_IGNORE_INVALID_POLICIES&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;&lt;SPAN style="font-family: Monaco, serif;"&gt;net stop certsvc&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;&lt;SPAN style="font-family: Monaco, serif;"&gt;net start certsvc&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 04:35:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587072#M519006</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-12-19T04:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587073#M519007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much for your prompt reply Hsing-Tsu! I did read that post earlier, however it doesn't really explain what the solution is or how to fix this on the CA server. "&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;This error may be&amp;nbsp; because the byod template is configured with the "all insurance policy" (OID = 2.5.29.32.0) and the CA server is unable to publish the certs using this template due to its policy restrictions. This should be workable once we enable all insurancy policy in the CA server. Looking at how to do this in the CA.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;This should be workable once we enable all insurancy policy in the CA server&lt;/SPAN&gt;" - Not sure what that ultimately means in terms of template or CA policy config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also found this note below with various ways of addressing this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://silkspundotcom.wordpress.com/2012/02/14/issuance-policies-with-a-ca-upgrade-to-windows-2008-r2-ad-cs-pki/" title="https://silkspundotcom.wordpress.com/2012/02/14/issuance-policies-with-a-ca-upgrade-to-windows-2008-r2-ad-cs-pki/"&gt;Issuance Policies with a CA Upgrade to Windows 2008 R2 AD CS PKI | SilkSpun&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess what you outlined earlier is noted as option one in the link below. Not sure though if this is a good thing since it seems to kind of override the behaviour and checks within the CA. So I am basically wondering if there is an issue with the pxGrid certificate template we configured in the CA or if there are some other knobs we need to tweak in the CA somewhere to make this work. Problem is who can we ask since this is more like a MS CA server specific question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 04:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587073#M519007</guid>
      <dc:creator>tlenzenh</dc:creator>
      <dc:date>2017-12-19T04:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587074#M519008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I meant is most of the certificate templates need no insurance policy; that is, we may leave it empty.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-12-18 at 8.58.37 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/114204_Screen Shot 2017-12-18 at 8.58.37 PM.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If one specified, then the CA needs to adhere to it and could cause problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 04:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587074#M519008</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-12-19T04:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587075#M519009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh ok, no worries. Let me try that. So I basically ignore whats shown in the Stealthwatch/ISE integration guide?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas Lenzenhofer&lt;/P&gt;&lt;P&gt;Network Security Consulting Engineer&lt;/P&gt;&lt;P&gt;Advanced Services / Security IDT&lt;/P&gt;&lt;P&gt;Cisco Systems APJC/Australia&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 05:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587075#M519009</guid>
      <dc:creator>tlenzenh</dc:creator>
      <dc:date>2017-12-19T05:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587076#M519010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am guessing John copied that from our "old" BYOD guide. It works fine if MS CA is by itself and customers reported problems when using a multi-tier MS CA. I would suggest you to send John a note.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 05:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587076#M519010</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-12-19T05:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587077#M519011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool that makes sense thanks! It worked fine in my lab on a standalone CA as you said, whereas the customer here has a 2-tier setup…&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas Lenzenhofer&lt;/P&gt;&lt;P&gt;Network Security Consulting Engineer&lt;/P&gt;&lt;P&gt;Advanced Services / Security IDT&lt;/P&gt;&lt;P&gt;Cisco Systems APJC/Australia&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 05:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587077#M519011</guid>
      <dc:creator>tlenzenh</dc:creator>
      <dc:date>2017-12-19T05:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 pxGrid - issue with CSR signing by CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587078#M519012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;Just as FYI – the screenshot you referred to yesterday – we had already had that setting earlier (empty list) and that itself didn’t work. We had to remove the ‘All Issuance Policies’ from the list under the ‘Extensions’ tab and then it worked right away.&lt;/P&gt;&lt;P&gt;Thanks again for pointing me into the right direction.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas Lenzenhofer&lt;/P&gt;&lt;P&gt;Network Security Consulting Engineer&lt;/P&gt;&lt;P&gt;Advanced Services / Security IDT&lt;/P&gt;&lt;P&gt;Cisco Systems APJC/Australia&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2017 02:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-pxgrid-issue-with-csr-signing-by-ca-server/m-p/3587078#M519012</guid>
      <dc:creator>tlenzenh</dc:creator>
      <dc:date>2017-12-20T02:21:48Z</dc:date>
    </item>
  </channel>
</rss>

