<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Allowing Expired Endpoint Certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-allowing-expired-endpoint-certificates/m-p/3511345#M519301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;We have a unique situation where we have a customer deployment where Windows machines are built with a machine certificate and stored in various locations ready for deployment. However the Issuing certificate Server expires soon, which means that these machine certificates would have expired before they are unboxed and allowed to do the normal certificate auto enrolment.&amp;nbsp; Cisco ISE will deny access by default to expired certificates, which is the default behaviour as i understand it, see extract below&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 25.0pt; font-family: 'inherit',serif; color: blue;"&gt;User and Endpoint Certificate Renewal&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 17.0pt; font-family: 'inherit',serif; color: blue;"&gt;By default, Cisco ISE rejects a request that comes from a device whose certificate has expired. However, you can change this default behavior and configure ISE to process such requests and prompt the user to renew the certificate&lt;/SPAN&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;."&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;Question 1&lt;/STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; - Is this for the ISE internal CA issued certs or any Organisation CA certs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;Question&amp;nbsp; 2&lt;/STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; - I found an article which says you can change this by looking at the "&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'inherit',serif; color: red;"&gt;CertRenewalRequired&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial',sans-serif; color: #58585b;"&gt;" Authorisation, will this work for a Organisations Microsoft CA issued certs, i..e Mycompany.com CA server cert on client, can we permit access to if the cert is expired using this authorisation check.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 21.5pt; font-family: 'inherit',serif; color: blue;"&gt;"Authorization Policy Condition for Certificate Renewal&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 17.0pt; font-family: 'inherit',serif; color: blue;"&gt;You can use the CertRenewalRequired simple condition (available by default) in authorization policy to ensure that a certificate (expired or about to expire) is renewed before Cisco ISE processes the request further."&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;Thanks Khalid&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Dec 2017 14:53:13 GMT</pubDate>
    <dc:creator>khalid_mahmood</dc:creator>
    <dc:date>2017-12-06T14:53:13Z</dc:date>
    <item>
      <title>Cisco ISE Allowing Expired Endpoint Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-allowing-expired-endpoint-certificates/m-p/3511345#M519301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;We have a unique situation where we have a customer deployment where Windows machines are built with a machine certificate and stored in various locations ready for deployment. However the Issuing certificate Server expires soon, which means that these machine certificates would have expired before they are unboxed and allowed to do the normal certificate auto enrolment.&amp;nbsp; Cisco ISE will deny access by default to expired certificates, which is the default behaviour as i understand it, see extract below&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 25.0pt; font-family: 'inherit',serif; color: blue;"&gt;User and Endpoint Certificate Renewal&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 17.0pt; font-family: 'inherit',serif; color: blue;"&gt;By default, Cisco ISE rejects a request that comes from a device whose certificate has expired. However, you can change this default behavior and configure ISE to process such requests and prompt the user to renew the certificate&lt;/SPAN&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;."&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;Question 1&lt;/STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; - Is this for the ISE internal CA issued certs or any Organisation CA certs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;Question&amp;nbsp; 2&lt;/STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt; - I found an article which says you can change this by looking at the "&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'inherit',serif; color: red;"&gt;CertRenewalRequired&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial',sans-serif; color: #58585b;"&gt;" Authorisation, will this work for a Organisations Microsoft CA issued certs, i..e Mycompany.com CA server cert on client, can we permit access to if the cert is expired using this authorisation check.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 21.5pt; font-family: 'inherit',serif; color: blue;"&gt;"Authorization Policy Condition for Certificate Renewal&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 17.0pt; font-family: 'inherit',serif; color: blue;"&gt;You can use the CertRenewalRequired simple condition (available by default) in authorization policy to ensure that a certificate (expired or about to expire) is renewed before Cisco ISE processes the request further."&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'inherit',serif;"&gt;Thanks Khalid&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2017 14:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-allowing-expired-endpoint-certificates/m-p/3511345#M519301</guid>
      <dc:creator>khalid_mahmood</dc:creator>
      <dc:date>2017-12-06T14:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Allowing Expired Endpoint Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-allowing-expired-endpoint-certificates/m-p/3511346#M519303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Khalid,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Machine authentication with certs is used with 802.1x&amp;nbsp; and Microsoft(MS) CA typically. Your MS CA infrastructure is integrated with AD. ISE internal CA will work with BYOD devices and cannot be used for 802.1x machine authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cert renewal policy conditions typically apply to internal CA. If you have an external CA, ISE does request in cert renewal if it is a SCEP proxy or configured as RA. Again this is applicable only for BYOD flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your best option at this point is not to use machine auth using certs and may be use machine credentials since this is already part of AD I assume. Then re-enroll your machines for certificate once the CA server is corrected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2017 20:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-allowing-expired-endpoint-certificates/m-p/3511346#M519303</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-12-06T20:20:46Z</dc:date>
    </item>
  </channel>
</rss>

