<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Should ISE certificate ise1.domain.local be imported to hosts? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4504033#M571093</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I imported the ISE Certificate, however, this time, a Self Signed one, an the error went away.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am using Cisco AnyConnect as an agent in the supplicant hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 07:56:57 GMT</pubDate>
    <dc:creator>laurathaqi</dc:creator>
    <dc:date>2021-11-17T07:56:57Z</dc:date>
    <item>
      <title>Should ISE certificate ise1.domain.local be imported to hosts?</title>
      <link>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4501881#M571028</link>
      <description>&lt;P&gt;Dear community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As part of the ISE Posture with AnyConnect, I have imported the Root certificate to all domain hosts via GPO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, am still getting a Certificate error of untrusted server, when AnyConnect tries to talk to ISE appliance during posture process. The ISE is signed by the same Root Cert which is imported in the Trusted Authority in the hosts computers. And that certificate is checked to be used for portals also. However, I did not import this certificate in all of the hosts of the domain. And only Root is imported.&lt;/P&gt;&lt;P&gt;So my question is as following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I also import the ISE certificate into this Trusted Authority in order to remove this error?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The guides are quite hard to decipher on this specific information.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 07:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4501881#M571028</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-11-12T07:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Should ISE certificate ise1.domain.local be imported to hosts?</title>
      <link>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4502920#M571048</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Should I also import the ISE certificate into this Trusted Authority in order to remove this error?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Please also import the intermediate certificate into the respective trust store on the client that is also a part of the chain.&amp;nbsp; Test, and see if your result changes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Out of curiosity, are you using NAM or native supp.?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 13:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4502920#M571048</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-11-15T13:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Should ISE certificate ise1.domain.local be imported to hosts?</title>
      <link>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4504033#M571093</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I imported the ISE Certificate, however, this time, a Self Signed one, an the error went away.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am using Cisco AnyConnect as an agent in the supplicant hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 07:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/should-ise-certificate-ise1-domain-local-be-imported-to-hosts/m-p/4504033#M571093</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-11-17T07:56:57Z</dc:date>
    </item>
  </channel>
</rss>

