<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trust Store error in ISE Intune Integration even after having ITL cert in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129176#M562050</link>
    <description>&lt;P&gt;First time seeing a post with 0 replies from the community!!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Aug 2020 10:48:00 GMT</pubDate>
    <dc:creator>pcno</dc:creator>
    <dc:date>2020-08-02T10:48:00Z</dc:date>
    <item>
      <title>Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4124332#M561888</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;We run a distributed deployment we have 2 X PAN 2 X PSN 2 X MNT.&lt;BR /&gt;I am trying to add MDM integration of Intune to ISE, Following are the steps done for it.&lt;BR /&gt;&lt;BR /&gt;Portal.azure.com, bail more, ITL 1-5 cert are kept inside the ISE trust store. Ise app registration in done in Intune and ISE PAN certificate is uploaded in there and the base 64 value of PAN has been added in Manifest,API permission are given as per document.&lt;BR /&gt;&lt;BR /&gt;But I am getting this trust store error as in attachment. Please tell me what I am missing here?&lt;BR /&gt;Do I need to upload all ITL &amp;amp; Portal certificate in each PSN node trust store?&lt;BR /&gt;Do I need to upload the PSN node certificate in Azure Manifest?&lt;BR /&gt;&lt;BR /&gt;According to document, only PAN cert is needed to upload in Azure app registration. and PAN primary nod only requires Trust store cert of ITL.&lt;BR /&gt;&lt;BR /&gt;Please help me on this, Refer to attachment.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 15:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4124332#M561888</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-23T15:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129176#M562050</link>
      <description>&lt;P&gt;First time seeing a post with 0 replies from the community!!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 10:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129176#M562050</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-08-02T10:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129187#M562053</link>
      <description>&lt;P&gt;This occurs when ISE is trying to access the Token Issuing URL and it is returning a certificate that the ISE is not trusting. Make sure the full CA chain is in ISE truststore. If the issue still persists after confirming that, perform packet captures and test connectivity to see what is being sent.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 11:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129187#M562053</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-08-02T11:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129194#M562054</link>
      <description>Also refer Step by Step integration guide to verify your config:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-integrate-microsoft-intune-with-ise-2-1-presentation/ta-p/3619502" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-integrate-microsoft-intune-with-ise-2-1-presentation/ta-p/3619502&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 02 Aug 2020 12:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4129194#M562054</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-08-02T12:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130077#M562086</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm having the same problem here. Followed those:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-intune-integration-question/m-p/4079471" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-intune-integration-question/m-p/4079471&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/td-p/4124332" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/td-p/4124332&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I'm currently trying to capture traffic to see if there's any clue but so far, we had no success.&lt;BR /&gt;&lt;BR /&gt;Did you get any luck finding a solution?&lt;BR /&gt;&lt;BR /&gt;Kr,</description>
      <pubDate>Tue, 04 Aug 2020 12:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130077#M562086</guid>
      <dc:creator>mchsmn</dc:creator>
      <dc:date>2020-08-04T12:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130088#M562087</link>
      <description>Thanks but this is really outdated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;</description>
      <pubDate>Tue, 04 Aug 2020 12:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130088#M562087</guid>
      <dc:creator>mchsmn</dc:creator>
      <dc:date>2020-08-04T12:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130216#M562094</link>
      <description>&lt;P&gt;Poongarg , All documents are very old even the setup azure has been changed and no longer the same menu options.&lt;BR /&gt;The thing is I was able to do MDM Check via ISE till July half then suddenly I started getting the Trust store error!!&lt;BR /&gt;&lt;BR /&gt;I wonder did any cert got changed recently and that is creating a trust store error.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 15:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130216#M562094</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-08-04T15:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130524#M562105</link>
      <description>The Portal.azure.com have below certificates in the certificate chain:&lt;BR /&gt;1. Baltimore CyberTrust Root&lt;BR /&gt;2. Microsoft IT TLS CA 2&lt;BR /&gt;3. Portal.azure.com&lt;BR /&gt;&lt;BR /&gt;We need to import the Baltimore CyberTrust Root certificate in the ISE Trusted Certificates Store as well.&lt;BR /&gt;If it is also imported then packet capture on PAN node is the next step for troubleshooting.&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Aug 2020 02:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130524#M562105</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-08-05T02:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130561#M562112</link>
      <description>What Poonam recommended make sense.  If all the required certificates are already there, then TCPdump would help us to understand ISE connections with the destination URL. To avoid any issue, export the cert's from PCAP and import in ISE trusted cert store.</description>
      <pubDate>Wed, 05 Aug 2020 05:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130561#M562112</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2020-08-05T05:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130611#M562113</link>
      <description>&lt;P&gt;This is true but upon inspection, we saw this url called: &lt;A href="https://fef.msub05.manage.microsoft.com/" target="_blank"&gt;https://fef.msub05.manage.microsoft.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We added his certificate even tough it's the same trust chain (msub05.jpg).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, we did a capture and got a "Fatal, certificate unknown" (pcap.jpg). After adding the whole new chain in the trust store, it finally worked (stamp2.login.jpg).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this help!&lt;/P&gt;&lt;P&gt;Take care,&lt;/P&gt;&lt;P&gt;Sim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 07:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4130611#M562113</guid>
      <dc:creator>mchsmn</dc:creator>
      <dc:date>2020-08-05T07:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trust Store error in ISE Intune Integration even after having ITL cert</title>
      <link>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4131452#M562158</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1083381" target="_self"&gt;mchsmn&lt;/A&gt;, Can you&amp;nbsp; please tell me that do you have anything extra than the below cert in your trust store?&lt;BR /&gt;&lt;BR /&gt;ITL 1-5&lt;BR /&gt;Portal.azure.com&lt;BR /&gt;Bailmore&lt;BR /&gt;&lt;BR /&gt;And are you puting in PAN primary trust store or in each PSN node?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 14:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trust-store-error-in-ise-intune-integration-even-after-having/m-p/4131452#M562158</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-08-06T14:30:02Z</dc:date>
    </item>
  </channel>
</rss>

