<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Select Pop up - Anyconnect in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395983#M567017</link>
    <description>&lt;P&gt;Mike, Can you suggest some exact example. We have tried to select the Issuer CN and mention the domain then selected 'matches' option but that not worked.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 10:13:35 GMT</pubDate>
    <dc:creator>AK002</dc:creator>
    <dc:date>2021-04-30T10:13:35Z</dc:date>
    <item>
      <title>Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395436#M566981</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Recently through GPU installed MS teams certificate on all Desktop machines, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now two Certificates are popping up on Desktop machines causing a hindrance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Wired connection is autostartup on Anyconnect supplicant and then its&amp;nbsp; giving a choice of two certificates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want to just automatically set the one with domain certificate to take effect&amp;nbsp;&amp;nbsp;- Trying to amend the configuration.xml file result in renaming it to configuration_bad and result not working.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where we need to take care of this configuration we tried to edit the any connect&amp;nbsp;xml but not helped.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any changes or configuration needed from ISE to set the same.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Attached the&amp;nbsp;popup message, The AnyConnect&amp;nbsp;asking the user to choose&amp;nbsp;the&amp;nbsp;certificates in the list to connect&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AK&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 12:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395436#M566981</guid>
      <dc:creator>AK002</dc:creator>
      <dc:date>2021-04-29T12:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395493#M566986</link>
      <description>&lt;P&gt;You can configure certificate matching using the NAM profile editor, which can be downloaded here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286281283/type/282364313/release/4.10.00093" target="_blank"&gt;Software Download - Cisco Systems&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Open up the AnyConnect NAM profile editor, then open configuration.xml.&amp;nbsp; Not sure what protocol you are using, but see the 'Credentials' tab &amp;amp; reference 'Certificate Matching Rule' section.&amp;nbsp; Then identify a unique attribute that differentiates between the two certs.&amp;nbsp; HTH!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395493#M566986</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-29T13:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395504#M566988</link>
      <description>&lt;P&gt;Mike, I think exactly what we have tried chooses the 'Use certificate matching' and tried to select issuer.CN and gave .xx.aaa.com, But when we tried that same message happening again. PFA&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 14:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395504#M566988</guid>
      <dc:creator>AK002</dc:creator>
      <dc:date>2021-04-29T14:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395559#M566993</link>
      <description>&lt;P&gt;Are you referencing a unique identifier that is not found on both certs? Double check to ensure that you are using the right criteria, by this I mean if you are using contains, then you can use a modified string to match.&amp;nbsp; If using EQUALS then you have to have the exact attribute.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 15:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395559#M566993</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-29T15:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395983#M567017</link>
      <description>&lt;P&gt;Mike, Can you suggest some exact example. We have tried to select the Issuer CN and mention the domain then selected 'matches' option but that not worked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 10:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4395983#M567017</guid>
      <dc:creator>AK002</dc:creator>
      <dc:date>2021-04-30T10:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4396276#M567024</link>
      <description>&lt;P&gt;Without knowing what the attributes are for each cert exactly I can't really point out an example that would relate to your case.&amp;nbsp; Also, I am not really sure I am following your 'matches' comment as the two options for certificate matching in the NAM profile editor are:&lt;/P&gt;
&lt;P&gt;'Equals' or 'Includes'&lt;/P&gt;
&lt;P&gt;Make sure that the CN mentioning the domain is not also a part of the other cert's CN.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 18:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4396276#M567024</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-30T18:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4396813#M567069</link>
      <description>&lt;P&gt;The AnyConnect Admin Guide has some details --&amp;nbsp;&lt;/P&gt;
&lt;UL class="ullinks"&gt;
&lt;LI class="link ulchildlink"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect410/administration/guide/b-anyconnect-admin-guide-4-10/configure_nam.html#task_37B4C9B1056146FC9D72DC2312916026" target="_blank"&gt;Set up Network Access Manager to Choose Correct Certificate&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If it not working for you, best to engage Cisco TAC for help.&lt;/P&gt;
&lt;P&gt;Note this known issue -- CSCvr54037&amp;nbsp;NAM PE not Saving user Defined EKU for Cert Matching Rule-Machine EAP-TLS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 02:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4396813#M567069</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-05-03T02:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Select Pop up - Anyconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4398680#M567166</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We just upgraded the cisco Any connect mobility client to 4.9 and now this started working as per the attributes specified under credientials tab.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvr54037" target="_blank" rel="noopener"&gt;CSCvr54037&lt;/A&gt;&amp;nbsp;- This bug specifies issue with 4.7 version may be the issue resides on the NAM editor and Any connect version&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your Help ..&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 10:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-select-pop-up-anyconnect/m-p/4398680#M567166</guid>
      <dc:creator>AK002</dc:creator>
      <dc:date>2021-05-06T10:09:55Z</dc:date>
    </item>
  </channel>
</rss>

