<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authenticate Cisco IP Phone to ISE using MIC Certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3184155#M555608</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to authenticate our IP Phones using the built in MIC certificate. &amp;nbsp;I am unable to find documentation on how to acheve this with ISE. &amp;nbsp;I found an older ACS document, but I find that there are many aspects that are different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have installed the CAP-RTP certs from our CUCM servers into the Trusted store in ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an authentication policy that allows wired 802.1x and EAP-TLS, and an authorization policy that allows EAP-TLS and a certificate with a subject that starts with CP-. &amp;nbsp;Could the Authentication policy be incorrectly setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get a 12514 error stating that there is an unknown CA in the client cert chain. &amp;nbsp;The documentation states that you need to have the two Cisco CA certs, and they are installed in ISE, however the older ones are disabled. &amp;nbsp;Could this be part of the issue? &amp;nbsp;Is there any harm in enabling them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:34:07 GMT</pubDate>
    <dc:creator>dan.letkeman</dc:creator>
    <dc:date>2020-02-21T18:34:07Z</dc:date>
    <item>
      <title>Authenticate Cisco IP Phone to ISE using MIC Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3184155#M555608</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to authenticate our IP Phones using the built in MIC certificate. &amp;nbsp;I am unable to find documentation on how to acheve this with ISE. &amp;nbsp;I found an older ACS document, but I find that there are many aspects that are different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have installed the CAP-RTP certs from our CUCM servers into the Trusted store in ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an authentication policy that allows wired 802.1x and EAP-TLS, and an authorization policy that allows EAP-TLS and a certificate with a subject that starts with CP-. &amp;nbsp;Could the Authentication policy be incorrectly setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get a 12514 error stating that there is an unknown CA in the client cert chain. &amp;nbsp;The documentation states that you need to have the two Cisco CA certs, and they are installed in ISE, however the older ones are disabled. &amp;nbsp;Could this be part of the issue? &amp;nbsp;Is there any harm in enabling them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3184155#M555608</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2020-02-21T18:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Cisco IP Phone to ISE using MIC Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3184919#M555609</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt;Can you share the complete config you've done on ise? &lt;BR /&gt;You're missing a trusted CA from CUCM. Have you exported all those certificates: Cisco_Root_CA_2048, Cisco_Manufacturing_CA, CAP-RTP-001, and CAP-RTP-002 ?&lt;BR /&gt;And imported them into ISE?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 16 Sep 2017 01:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3184919#M555609</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-09-16T01:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Cisco IP Phone to ISE using MIC Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3185081#M555610</link>
      <description>&lt;P&gt;I had to enable the older Cisco Root certs that were installed on ISE. &amp;nbsp; By default only the two newer Cisco Root certs are enabled.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Sep 2017 23:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3185081#M555610</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2017-09-16T23:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Cisco IP Phone to ISE using MIC Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3356731#M555611</link>
      <description>&lt;P&gt;Dan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Was that all you had to do? Also, can you share the screenshot of the policy you created on ISE? I am getting ready to do a similar deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Francisco Padron.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 14:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3356731#M555611</guid>
      <dc:creator>fpadron</dc:creator>
      <dc:date>2018-03-28T14:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Cisco IP Phone to ISE using MIC Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3356799#M555612</link>
      <description>&lt;P&gt;Here you go.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Phone.png" style="width: 752px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/9514iBCB3D8AA9CFED767/image-size/large?v=v2&amp;amp;px=999" role="button" title="Phone.png" alt="Phone.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 15:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3356799#M555612</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2018-03-28T15:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Cisco IP Phone to ISE using MIC Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3357003#M555613</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;
&lt;P&gt;Your policy looks ok.&lt;/P&gt;
&lt;P&gt;Just do a capture on ISE (host SWITCH_IP) and check in wireshark the phone cert. (it will not be that hard to see)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 19:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-cisco-ip-phone-to-ise-using-mic-certificate/m-p/3357003#M555613</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2018-03-28T19:36:22Z</dc:date>
    </item>
  </channel>
</rss>

