<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488114#M519669</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TAC came back and said I should not use internal ISE CA or an intermediate cert.&amp;nbsp; Instead I should just use the internal cert that handles the ISE management, dot1x and portal functions.&amp;nbsp; When I did that I was able to register my apple device.&amp;nbsp; They provided a workable solution.&amp;nbsp; I'm good for now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Nov 2017 21:39:07 GMT</pubDate>
    <dc:creator>aprildanos</dc:creator>
    <dc:date>2017-11-20T21:39:07Z</dc:date>
    <item>
      <title>ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488109#M519641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;2 node deployment.&amp;nbsp; Cannot get my iPhone to register to ISE BYOD portal.&amp;nbsp; Fails when installing Profile Service with an invalid server certificate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have tried:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Active Directory Server as the Root and ISE as a Subordinate CA &lt;/P&gt;&lt;P&gt;2) ISE is the Root CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way it fails at the install Profile Service part.&amp;nbsp; The profile is green and says it has been verified. Windows SPW works fine.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have gone into Settings &amp;gt;&amp;nbsp; About &amp;gt; etc on the phone and trusted the ISE root certificate.&amp;nbsp; Running the logs on iOS console have not yielded any information. Was getting same results on iOS 10.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISE is trying to install 4 certs: Endpoints, ISE Root, ISE Services and ISE SubCA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The iPhone did register on time with my AD server as the Root CA over ISE but that was only once.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have TAC case open and making no headway other than to possibly recommend I call Apple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any suggestions as I am at the end of the line to get ISE BYOD and Apple working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 20:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488109#M519641</guid>
      <dc:creator>aprildanos</dc:creator>
      <dc:date>2017-11-20T20:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488110#M519644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend you escalate with the TAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you are on the latest patch as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You maybe using a certificate that the apple ios device doesn’t like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Out of curiosity what vendors well know cert are you using? I assume you are using a well known cert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 20:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488110#M519644</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-20T20:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488111#M519648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you also tried using the internal CA on ISE and not using an external PKI? You will have better results using the default settings&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 20:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488111#M519648</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-20T20:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488112#M519655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did try using the internal ISE CA. That was my second choice. First Microsoft and then ISE by itself.&amp;nbsp; Not well-known signed certificate.&amp;nbsp; I am on the latest ISE patch.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Per TAC engineer, ISE BYOD and Apple are not supported when ISE provides SCEP services.&amp;nbsp;&amp;nbsp; Their recommendation, and only way to get it working, is have my internal Microsoft CA be the SCEP server.&amp;nbsp; This is because Apple supports 3 cert chain or less.&amp;nbsp; ISE adds 4 certs when being Root authority and 5 certs when acting as an Intermediate.&amp;nbsp; Per TAC, apple does not like that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Curious thing is the certificate profile was accepted once.&amp;nbsp; But don't remember what happened to make that happen. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for help from the community as I do not want to set up my AD server as a SCEP server but seem to have no choice.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 21:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488112#M519655</guid>
      <dc:creator>aprildanos</dc:creator>
      <dc:date>2017-11-20T21:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488113#M519661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to escalate to the TAC duty manager this is incorrect.  ISE internal CA with apple BYOD are most definitely supported. We have this running in all our demos as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you deploy a well-known certificate, otherwise you’re onboarding of apple devices will not flow correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommend checking out this demo as well where you can see a working setup in action. You can login with your CCO ID to a working ISE setup. If you have an AP you can even connect to the setup and try it out.&lt;/P&gt;&lt;P&gt;https://dcloud2-rtp.cisco.com/content/demo/363207?returnPathTitleKey=favourites-view&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is only 3 certs in the chain with internal CA setup&lt;/P&gt;&lt;P&gt;Admin node is the ROOT&lt;/P&gt;&lt;P&gt;Policy services is Node-ca (signed by root)&lt;/P&gt;&lt;P&gt;Policy services is the sub-ca (signed by sub-ca)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 21:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488113#M519661</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-20T21:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488114#M519669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TAC came back and said I should not use internal ISE CA or an intermediate cert.&amp;nbsp; Instead I should just use the internal cert that handles the ISE management, dot1x and portal functions.&amp;nbsp; When I did that I was able to register my apple device.&amp;nbsp; They provided a workable solution.&amp;nbsp; I'm good for now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 21:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488114#M519669</guid>
      <dc:creator>aprildanos</dc:creator>
      <dc:date>2017-11-20T21:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2P4 Apple iPhone7 vers 11 BYOD will not Register</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488115#M519674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok glad you have it running. Keep in mind you will need to deploy a well known cert in your setup for it to scale and work in production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE with its internal CA for BYOD is the recommended way for deploying in production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There might be some semantic issues going on here as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 21:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2p4-apple-iphone7-vers-11-byod-will-not-register/m-p/3488115#M519674</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-20T21:51:17Z</dc:date>
    </item>
  </channel>
</rss>

