<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Admin Users can't log into Certificate Provisioning Portal in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453961#M527533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That explains that.&amp;nbsp; I never created a provisioning portal only used the default one, so I wouldn't have looked at that particular documentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 20 Aug 2017 15:31:15 GMT</pubDate>
    <dc:creator>GQ</dc:creator>
    <dc:date>2017-08-20T15:31:15Z</dc:date>
    <item>
      <title>Admin Users can't log into Certificate Provisioning Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453956#M527528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;trying to login to the the Cert Provisioning Portal as the Admin users...&amp;nbsp; because those are the only ones powerful enough to bulk create certificates with different CNs.&amp;nbsp; Only get invalid user.&amp;nbsp; Any additional superadmin users have the same problem.&amp;nbsp; Internal users can log in to the portal but not the Admin users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a misconfig but I can't see what.&amp;nbsp; Is this working for anyone else?&amp;nbsp; (didn't in my home or in the dcloud environment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-08-18 at 10.17.45 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/110621_Screen Shot 2017-08-18 at 10.17.45 AM.png" style="height: 117px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 17:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453956#M527528</guid>
      <dc:creator>GQ</dc:creator>
      <dc:date>2017-08-18T17:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Users can't log into Certificate Provisioning Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453957#M527529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically the case of validating the Identity Sequence for the portal.&amp;nbsp; I suspect Internal Users are in current sequence, but admin users are separate class of user.&amp;nbsp; Try creating new internal user (or use existing) and then add internal user as super admin user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 21:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453957#M527529</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-18T21:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Users can't log into Certificate Provisioning Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453958#M527530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig is correct. The admin users need first be created as internal users and then added into admin users by selecting from network access users with either Super Admin or ERS Admin group. Else, we may use external admin users in an AD group mapped either of those two admin groups.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-08-18 at 2.45.31 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/110619_Screen Shot 2017-08-18 at 2.45.31 PM.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 21:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453958#M527530</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-18T21:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Users can't log into Certificate Provisioning Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453959#M527531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nice.&amp;nbsp; Sorry if that was documented somewhere and I didn't see it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 22:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453959#M527531</guid>
      <dc:creator>GQ</dc:creator>
      <dc:date>2017-08-18T22:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Users can't log into Certificate Provisioning Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453960#M527532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The info is somewhat buried in &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_010000.html#task_461AA6C86B36415292F6E6432334AEB9"&gt;Create a Certificate Provisioning Portal&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;There are two types of users who can access the Certificate Provisioning portal:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A name="task_461AA6C86B36415292F6E6432334AEB9__li_7FCE327169464455B5DEA5EECCBB992C"&gt;&lt;/A&gt; Internal or external users with administrative privileges—Can generate certificate(s) for themselves as well as for others.&lt;/LI&gt;
&lt;LI&gt;&lt;A name="task_461AA6C86B36415292F6E6432334AEB9__li_6BDDD77D9FD54ED7BF8AA10E74389158"&gt;&lt;/A&gt; All other users—Can generate certificate(s) only for themselves.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Users (network access users) who are assigned the Super Admin or ERS Admin role have access to this portal and can request certificates for others.&lt;STRONG&gt; &lt;/STRONG&gt;However,&lt;STRONG&gt; &lt;SPAN style="color: #ff0000;"&gt;if you create a new internal admin user and assign the Super Admin or ERS Admin role, the internal admin user will not have access to this portal.&lt;/SPAN&gt; &lt;SPAN style="color: #008000;"&gt;You must first create a network access user and then add the user to the Super Admin or ERS Admin group.&lt;/SPAN&gt; Any existing network access users who are added to the Super Admin or ERS Admin group will have access to this portal.&lt;/STRONG&gt; To create an administrator account to access the Certificate Provisioning portal: &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A name="task_461AA6C86B36415292F6E6432334AEB9__li_4AE75422B3464307ADB7B1ED9DE58407"&gt;&lt;/A&gt;Add an internal user (Administration &amp;gt; Identity Management &amp;gt; Identities &amp;gt; Users &amp;gt; Add).&lt;/LI&gt;
&lt;LI&gt;&lt;A name="task_461AA6C86B36415292F6E6432334AEB9__li_D2CAB97529014065A6F1540EAC334098"&gt;&lt;/A&gt;Add the user to the Super Admin or ERS Admin group (Administration &amp;gt; Admin Access &amp;gt; Administrators &amp;gt; Admin Users &amp;gt; Add &amp;gt; Select from existing network access user). The user is now both an internal network access user and a Super Admin or ERS Admin user.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 22:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453960#M527532</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-18T22:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Users can't log into Certificate Provisioning Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453961#M527533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That explains that.&amp;nbsp; I never created a provisioning portal only used the default one, so I wouldn't have looked at that particular documentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Aug 2017 15:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/admin-users-can-t-log-into-certificate-provisioning-portal/m-p/3453961#M527533</guid>
      <dc:creator>GQ</dc:creator>
      <dc:date>2017-08-20T15:31:15Z</dc:date>
    </item>
  </channel>
</rss>

