<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 - Subject Alt Name or Calling-Station-ID case sensitive? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479086#M527753</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try creating a new authorization policy rule and see if that works.&lt;/P&gt;&lt;P&gt;CSCvf47170 is seen at a couple beta customers' setups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Aug 2017 04:01:18 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-08-10T04:01:18Z</dc:date>
    <item>
      <title>ISE 2.3 - Subject Alt Name or Calling-Station-ID case sensitive?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479085#M527751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has there been a change between ISE 2.0 and 2.3 in the case sensitivity of the Certificate:Subject Alternative Name and/or Radius:Calling-Station-ID attributes or the operators (EQUALS, MATCHES, CONTAINS)?&lt;/P&gt;&lt;P&gt;After upgrading from ISE 2.0 p4 to 2.3, the AuthZ policies based upon 'Certificate:Subject Alternative Name EQUALS Radius:Calling-Station-ID' are failing to hit.&lt;/P&gt;&lt;P&gt;I've tried using the EQUALS and MATCHES operators, but both fail. In the log details, these attributes are different cases.&lt;/P&gt;&lt;P&gt;Subject Alternative Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00-DB-DF-58-64-A2&lt;/P&gt;&lt;P&gt;Calling Station Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00-db-df-58-64-a2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change the Calling-Station-ID attribute to the string for the SAN (00-DB-DF-58-64-A2), the rule hits.&lt;/P&gt;&lt;P&gt;If I change the operator to CONTAINS, it also works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this expected/known behaviour with ISE 2.3?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 03:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479085#M527751</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2017-08-10T03:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Subject Alt Name or Calling-Station-ID case sensitive?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479086#M527753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try creating a new authorization policy rule and see if that works.&lt;/P&gt;&lt;P&gt;CSCvf47170 is seen at a couple beta customers' setups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 04:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479086#M527753</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-10T04:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Subject Alt Name or Calling-Station-ID case sensitive?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479087#M527756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi HS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does work if I create a new AuthZ rule, but does not if I duplicate the existing rule.&lt;/P&gt;&lt;P&gt;Is this likely to be part of the same bug listed above, or should I open a TAC case to have a new bug opened?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue will complicate any ISE upgrade if we have to recreate the rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 04:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479087#M527756</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2017-08-10T04:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Subject Alt Name or Calling-Station-ID case sensitive?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479088#M527757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will check with DE and see whether he needs debug logs from you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 04:15:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-subject-alt-name-or-calling-station-id-case-sensitive/m-p/3479088#M527757</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-10T04:15:38Z</dc:date>
    </item>
  </channel>
</rss>

