<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does iOS devices needs to accept the public signed cert in Guest/CWA flow ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4089640#M560556</link>
    <description>&lt;P&gt;(updating the thread to help others)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: -webkit-standard; font-size: medium; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;This behavior is for DOT1X only and not applicable to Guest/CWA flow&lt;/SPAN&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2020 22:14:56 GMT</pubDate>
    <dc:creator>musultan</dc:creator>
    <dc:date>2020-05-20T22:14:56Z</dc:date>
    <item>
      <title>Does iOS devices needs to accept the public signed cert in Guest/CWA flow ?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4088172#M560489</link>
      <description>&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration: none; display: inline !important; float: none;"&gt;For the Guest/CWA flow, does Apple iOS devices needs to ACCEPT/Validate the publicly trusted certificates like PEAP or 802.1x ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration: none; display: inline !important; float: none;"&gt;Reference &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/compatibility/ise_sdt.html#pgfId-141382" target="_self"&gt;Link&lt;/A&gt;: &lt;/SPAN&gt;When Apple iOS devices use Protected Extensible Authentication Protocol (PEAP) with Cisco ISE or 802.1x, certificate warnings might be displayed even for publicly trusted certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another Reference &lt;A href="https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_self"&gt;Link&lt;/A&gt;:&amp;nbsp;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration: none; display: inline !important; float: none;"&gt;When an iOS client first communicates to a PSN it will not explicitly trust the PSN certificate, even though a trusted Certificate Authority has signed the certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="-webkit-user-select: all; color: #000000; background-color: #ffffff; caret-color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="-webkit-user-select: all; color: #000000; background-color: #ffffff; caret-color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration: none; display: inline !important; float: none;"&gt;Does this limitation applicable to Guest/CWA flow for iOS devices or not ?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV style="-webkit-user-select: all; color: #000000; background-color: #ffffff; caret-color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;Please advise.&lt;/DIV&gt;
&lt;DIV style="-webkit-user-select: all; color: #000000; background-color: #ffffff; caret-color: #000000; font-family: -apple-system, 'Segoe UI', 'Segoe UI Emoji', sans-serif, Meiryo; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 18 May 2020 19:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4088172#M560489</guid>
      <dc:creator>musultan</dc:creator>
      <dc:date>2020-05-18T19:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Does iOS devices needs to accept the public signed cert in Guest/CWA flow ?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4089107#M560534</link>
      <description>&lt;P&gt;Any update on this ?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 06:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4089107#M560534</guid>
      <dc:creator>musultan</dc:creator>
      <dc:date>2020-05-20T06:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Does iOS devices needs to accept the public signed cert in Guest/CWA flow ?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4089640#M560556</link>
      <description>&lt;P&gt;(updating the thread to help others)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: -webkit-standard; font-size: medium; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;This behavior is for DOT1X only and not applicable to Guest/CWA flow&lt;/SPAN&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 22:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-ios-devices-needs-to-accept-the-public-signed-cert-in-guest/m-p/4089640#M560556</guid>
      <dc:creator>musultan</dc:creator>
      <dc:date>2020-05-20T22:14:56Z</dc:date>
    </item>
  </channel>
</rss>

