<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.0 Cert Chain Android in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3780672#M543649</link>
    <description>&lt;P&gt;I recently updated a couple certs on our ISE server. I applied the same cert to the default portal policy as well as EAP Authentication. We went from an OV cert to an EV cert which required an intermediate cert to be installed to the ISE server. I am not having any problems with anything except the Guest Portal on Android.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is happening is the Certificate chain is not complete on the android devices. All laptops are listing it as valid cert as they are listing the root and intermediate certs. I can manually install the intermediate cert on my android&amp;nbsp;devices and have it show as valid, however that should not be needed as it is installed on the ISE server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On top of that problem, we are recieving the portal redirect page (connectivitycheck.gstatic.com) and no portal. The only way I have been able to get around this is by clicking "connect as is" and open chrome; I then navigate to "connectivitycheck.gstatic.com". Then I am redirected to the correct Guest Portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 08:53:54 GMT</pubDate>
    <dc:creator>MattD2010</dc:creator>
    <dc:date>2019-03-11T08:53:54Z</dc:date>
    <item>
      <title>ISE 2.0 Cert Chain Android</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3780672#M543649</link>
      <description>&lt;P&gt;I recently updated a couple certs on our ISE server. I applied the same cert to the default portal policy as well as EAP Authentication. We went from an OV cert to an EV cert which required an intermediate cert to be installed to the ISE server. I am not having any problems with anything except the Guest Portal on Android.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is happening is the Certificate chain is not complete on the android devices. All laptops are listing it as valid cert as they are listing the root and intermediate certs. I can manually install the intermediate cert on my android&amp;nbsp;devices and have it show as valid, however that should not be needed as it is installed on the ISE server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On top of that problem, we are recieving the portal redirect page (connectivitycheck.gstatic.com) and no portal. The only way I have been able to get around this is by clicking "connect as is" and open chrome; I then navigate to "connectivitycheck.gstatic.com". Then I am redirected to the correct Guest Portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3780672#M543649</guid>
      <dc:creator>MattD2010</dc:creator>
      <dc:date>2019-03-11T08:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.0 Cert Chain Android</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3780773#M543663</link>
      <description>I believe your issue could possibly stem from the certificate issue you are facing.  Does the redirect work after you manually install the intermediate certificate on the device? If so then I will point you to this known issue. &lt;BR /&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj04703/" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj04703/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Now as for the certificate issue you have.  You are seeing a legitimate invalid certificate warning if the intermediate certificate is missing from Android.  Having the root and intermediate installed on the ISE server only allows the ISE deployment to trust that certificate. The trust store on the device, in this case Android, has to have the complete certificate chain installed to trust the issuer, both root and any intermediates doing the signing.</description>
      <pubDate>Wed, 16 Jan 2019 05:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3780773#M543663</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-01-16T05:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.0 Cert Chain Android</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3864284#M543674</link>
      <description>&lt;P&gt;Hi Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're experiencing the exact same problem, though not limited to Android, but all devices that uses Google Chrome. The workaround, until we have found a prober solution, is to use other browsers than Google Chrome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ditlev&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 07:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-cert-chain-android/m-p/3864284#M543674</guid>
      <dc:creator>Ditlev Weinreich</dc:creator>
      <dc:date>2019-05-29T07:17:49Z</dc:date>
    </item>
  </channel>
</rss>

