<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network Setup Assistant Certificate Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585601#M521252</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the network setup assistant run how does is select and push the correct certificate to a machine?&lt;/P&gt;&lt;P&gt;Even in the BYOD setup when you select Certificate group tag the self signed is used. Deleted the self sign and the public certificate is used now. Users still get promoted to install the ROOT certificate even though this cert is a public cert with the ROOT certificate installed on the machine. How do I trouble shoot this so there is almost no user interaction for this. The browser does not have any issued on the portal when you register your device is only when the network setup assistant runs. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Sep 2017 07:54:12 GMT</pubDate>
    <dc:creator>chrisvanwyk</dc:creator>
    <dc:date>2017-09-28T07:54:12Z</dc:date>
    <item>
      <title>Network Setup Assistant Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585601#M521252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the network setup assistant run how does is select and push the correct certificate to a machine?&lt;/P&gt;&lt;P&gt;Even in the BYOD setup when you select Certificate group tag the self signed is used. Deleted the self sign and the public certificate is used now. Users still get promoted to install the ROOT certificate even though this cert is a public cert with the ROOT certificate installed on the machine. How do I trouble shoot this so there is almost no user interaction for this. The browser does not have any issued on the portal when you register your device is only when the network setup assistant runs. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 07:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585601#M521252</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-09-28T07:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Network Setup Assistant Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585602#M521253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes if you replace your ISE cert you need to use it for your portals&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be explained in the admin guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What operating system are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like it’s Apple iOS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apple unfortunately has to accept the cert even though it’s a well known one, when you start the process you must accept it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you are running multiple psns the best practice regardless is to use a certificate with a wildcard in the SAN so when you roam between psns you’re not required to accept the cert at every new radius server seen, this is also in the admin guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see our BYOD Page off http://cs.co/ISE-community for more info&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 11:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585602#M521253</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-28T11:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Network Setup Assistant Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585603#M521255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px; background-color: #f6f6f6;"&gt;The correct cert is tagged for portal use. The issue is not the portal it is the network setup assistant that you download. When it installs the native supplicant/profile it pushes a certificate to the machine. How do set that part?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 12:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585603#M521255</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-09-28T12:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Network Setup Assistant Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585604#M521257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is how it working today. ISE can't check or assume the client device has the root certificate for ISE EAP server, so it will prompt to install it regardless.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Sep 2017 02:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585604#M521257</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-29T02:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Network Setup Assistant Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585605#M521259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see even when you have selected not to prompt the user it still pops up. Well suppose the client will have to live with it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Sep 2017 10:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585605#M521259</guid>
      <dc:creator>chrisvanwyk</dc:creator>
      <dc:date>2017-09-29T10:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Network Setup Assistant Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585606#M521261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;The Windows-only option "Do not prompt user to authorize new servers or trusted certification authorities" is for after BYOD and certificate provisioning and during EAP-TLS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Oct 2017 20:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/network-setup-assistant-certificate-issue/m-p/3585606#M521261</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-10-02T20:15:28Z</dc:date>
    </item>
  </channel>
</rss>

