<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EAP cert change - problems on Apple IOS devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442886#M536794</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Hi all,&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;A lot of iPhones and iPads has been provisioned by ISE with NSP. This works fine and everyone is happy. Now comes the time to renew the EAP certificate of the ISE installation.&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;The new certificate has the same common name and the same root CA, but another intermediate/issuing CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;When the EAP certificate is changed on ISE, the provisioned I devices are unable to connect to the network again, until the provisioned profile on the device is uninstalled and the device is reprovisioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;If we test on a manual configured device, the device is also unable to connect to the wireless, but in this case it is enough to just accept the new certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Are there any workarounds to this issue, so the endusers only has to accept the new certificate or do nothing at all?&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Best regards&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Tue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Dec 2016 09:37:31 GMT</pubDate>
    <dc:creator>tuenoerg</dc:creator>
    <dc:date>2016-12-06T09:37:31Z</dc:date>
    <item>
      <title>EAP cert change - problems on Apple IOS devices</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442886#M536794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Hi all,&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;A lot of iPhones and iPads has been provisioned by ISE with NSP. This works fine and everyone is happy. Now comes the time to renew the EAP certificate of the ISE installation.&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;The new certificate has the same common name and the same root CA, but another intermediate/issuing CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;When the EAP certificate is changed on ISE, the provisioned I devices are unable to connect to the network again, until the provisioned profile on the device is uninstalled and the device is reprovisioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;If we test on a manual configured device, the device is also unable to connect to the wireless, but in this case it is enough to just accept the new certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Are there any workarounds to this issue, so the endusers only has to accept the new certificate or do nothing at all?&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Best regards&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Tue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2016 09:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442886#M536794</guid>
      <dc:creator>tuenoerg</dc:creator>
      <dc:date>2016-12-06T09:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: EAP cert change - problems on Apple IOS devices</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442887#M536795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tue, can you provide the details on the setup? What ISE version with patch when the certificates were issued and what version are they on now? Is it using internal CA or using SCEP for BYOD?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2016 21:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442887#M536795</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-12-06T21:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: EAP cert change - problems on Apple IOS devices</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442888#M536796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should be working as intended. The NSP Profile should provision trust certificates to the Device, if you replace the trust chain while renewing the certificate of the ISE the device isn't aware of the new trust chain and restricts the communication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2016 07:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442888#M536796</guid>
      <dc:creator>Oliver Laue</dc:creator>
      <dc:date>2016-12-07T07:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: EAP cert change - problems on Apple IOS devices</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442889#M536797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN lang="EN-US" style="color: #1f497d;"&gt;The iDevices are primary provisioned from ISE 1.2, but also 1.3 and 1.4. Currently the ISE is running 2.1 patch 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN lang="EN-US" style="color: #1f497d;"&gt;They are SCEP enrolled from a MS infrastructure&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 07:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442889#M536797</guid>
      <dc:creator>tuenoerg</dc:creator>
      <dc:date>2016-12-08T07:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: EAP cert change - problems on Apple IOS devices</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442890#M536798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tue, if still having issues and if not done already please contact TAC for further assistance on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 19:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-cert-change-problems-on-apple-ios-devices/m-p/3442890#M536798</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-12-08T19:42:08Z</dc:date>
    </item>
  </channel>
</rss>

