<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate/Private Key validation failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558263#M520133</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again yes you can use self signed certificate for different portals.Just go in certificate authority system certificates choose self-sign certificate&amp;nbsp; and edit it to use for portals .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Nov 2017 09:33:42 GMT</pubDate>
    <dc:creator>ognyan.totev</dc:creator>
    <dc:date>2017-11-10T09:33:42Z</dc:date>
    <item>
      <title>Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558260#M520130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Facing an issue while importing certificate in the ISE 2.3 PoV. The onsite partner has clarified that the CSR file created and signed by the CA (digicert is used for signing the request) has been created as per the documented process but at the time of importing throws the error of Certificate/Private Key validation failed. The error is as attached here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly suggest for any specific conditions to be checked on the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 07:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558260#M520130</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2017-11-07T07:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558261#M520131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is because missing ROOT CA in trusted store .This will help you &lt;A href="https://community.cisco.com/docs/DOC-68164"&gt;How To: Implement ISE Server-Side Certificates&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 09:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558261#M520131</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2017-11-07T09:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558262#M520132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have managed to solve the issue with wildcard certificate signed by CSR generated from ISE. We also understand that the customer is currently having a wildcard certificate in their internal CA hence we need the wildcard certificate for the ISE portals and functionalities which is not working since the Windows clients rejects certificate &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;with * in the CN name. In this case if we uncheck the &lt;SPAN lang="EN-GB" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;Validate Server Certificate the redirection but still it is not working. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;SPAN lang="EN-GB" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;SPAN lang="EN-GB" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Kindly clarify if we can use self signed certificate to achieve the ISE AAA, BYOD and posture capabilities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:27:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558262#M520132</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2017-11-10T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558263#M520133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again yes you can use self signed certificate for different portals.Just go in certificate authority system certificates choose self-sign certificate&amp;nbsp; and edit it to use for portals .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558263#M520133</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2017-11-10T09:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558264#M520134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Self signed cents in testing will fail for some clients! For example Apple iOS byod onboarding in latest builds has been secured by Apple and will present awful onboarding experience for the user as they will have to manually trust certificate after going through byod flow and have to go through it again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guest redirects may fail in latest browsers as vendors are cracking down on bad certificate and best practice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not deploy self signed certs in production&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see admin guide recommendation of using well known certificate with wildcard in the SAN for a good solution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0110.html?bookSearch=true#concept_8ECCCAF1252E40DDB9A786C0AC7BC3B2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 12:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558264#M520134</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-10T12:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558265#M520135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the clarification and suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will work on the same and let you know in case of any further queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Yogesh Madhekar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 06:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558265#M520135</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2017-11-14T06:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558266#M520136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a document for guest wired access ,what kind of acl you use,&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html"&gt;Central Web Authentication with a Switch and Identity Services Engine Configuration Example - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can check &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/compatibility/ise_sdt.html" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/compatibility/ise_sdt.html"&gt;Cisco Identity Services Engine Network Component Compatibility, Release 2.3 - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 08:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558266#M520136</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2017-11-15T08:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558267#M520137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using self signed certificate but the issue is that the redirection is not working, getting the error screenshot as mentioned above with error as stated here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After diagnosing the issue, it has been found that the Radius Authentication is failing on the Cisco Attribute Value (Cisco AVpair) "coa-skip-logical-profile="&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone got any idea into this error?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Nov 2017 04:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558267#M520137</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2017-11-16T04:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558268#M520138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;call the tac to debug switching issues &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Nov 2017 12:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558268#M520138</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-16T12:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558269#M520139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Known bugs:&lt;/P&gt;&lt;P&gt;CSCvg70582 (ISE bug)&lt;/P&gt;&lt;P&gt;CSCsx97093 (Switch bug)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Nov 2017 19:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/3558269#M520139</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-16T19:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate/Private Key validation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/4031743#M520140</link>
      <description>&lt;P&gt;I had the same problem today, 2/17/2020.&lt;/P&gt;&lt;P&gt;The problem is the format of the certificates.&lt;/P&gt;&lt;P&gt;The Certificate must be in .PEM or .DER format.&lt;/P&gt;&lt;P&gt;The Private Key must be in .KEY format.&lt;/P&gt;&lt;P&gt;Obeying these requirements, and using the correct password, the procedure works.&lt;/P&gt;&lt;P&gt;Here I imported DigiCert's Root, but I don't know if this step is really necessary, in any case it doesn't hurt.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 18:31:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-private-key-validation-failed/m-p/4031743#M520140</guid>
      <dc:creator>Douglas Koja</dc:creator>
      <dc:date>2020-02-18T18:31:43Z</dc:date>
    </item>
  </channel>
</rss>

