<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE certificate issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632902#M575529</link>
    <description>&lt;P&gt;create another A entry for ISE01 and test it.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 06:56:25 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-06-16T06:56:25Z</dc:date>
    <item>
      <title>ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632482#M575509</link>
      <description>&lt;P&gt;I am having a problem binding a CSR and the resulting certificate. I get the error&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;"Certificate must contain the FQDN...". Research has shown that this has occurred&amp;nbsp;before and was related to a SAN not matching the domain. I have verified that they do match, no leading or trailing spaces; no 0o/1l typos. My cert looks like:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(The machine name is ise01)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Multi-use&lt;/P&gt;
&lt;P&gt;Allow Wildcard Certificates&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CN: ise.client.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;SAN: ise.client.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*.client.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ise01.client.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I checked the hostname in CLI and even made sure the virtual machine name was all matching. Does anyone know what log would contain failures for this? I tried recursive grep'ing for different words from the support bundle and could not find anything. What else would you recommend. Thank you for your time.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632482#M575509</guid>
      <dc:creator>atheio</dc:creator>
      <dc:date>2022-06-15T15:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632483#M575510</link>
      <description>&lt;P&gt;Is the FQDN of ISE actually ise01.client.com?&amp;nbsp; Or is it something else?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632483#M575510</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-06-15T15:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632485#M575511</link>
      <description>&lt;P&gt;Yes it is.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632485#M575511</guid>
      <dc:creator>atheio</dc:creator>
      <dc:date>2022-06-15T15:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632522#M575516</link>
      <description>&lt;P&gt;ise01.client.com&amp;nbsp; - is this resolving in your nslookup ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 17:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632522#M575516</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-15T17:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632547#M575520</link>
      <description>&lt;P&gt;No it doesn't sir. This ISE server will be primary (10.1.1.134) and a secondary. (10.1.1.135). I wasn't sure if I needed to make the "ISE-cube" first or apply certificates. I have only created A-records pointing ise.client.com to those IPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632547#M575520</guid>
      <dc:creator>atheio</dc:creator>
      <dc:date>2022-06-15T18:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632902#M575529</link>
      <description>&lt;P&gt;create another A entry for ISE01 and test it.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 06:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4632902#M575529</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-16T06:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633163#M575533</link>
      <description>&lt;P&gt;Ok, I added an A record for ISE01, generated the CSR and I get the same error when I try to bind the new cert to the csr. Should I add the machine hostname to the SAN field?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ex: ise.client.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; *.client.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; ise01.client.com&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 13:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633163#M575533</guid>
      <dc:creator>atheio</dc:creator>
      <dc:date>2022-06-16T13:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633232#M575540</link>
      <description>&lt;P&gt;Machine hostname?&amp;nbsp; I thought the ISE hostname was ise01.client.com?&amp;nbsp; Is the DNS ise01.client.com but the actual hostname of the ISE node something else?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 14:47:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633232#M575540</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-06-16T14:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633293#M575544</link>
      <description>&lt;P&gt;Sorry, I think I am muddying the water. Here is a diagram of the setup. Do I need to add ise01.client.com and ise02.client.com to the SAN fields?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-06-16 at 12.34.29 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/153963i10F8D34382FBF15C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2022-06-16 at 12.34.29 PM.png" alt="Screen Shot 2022-06-16 at 12.34.29 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 16:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633293#M575544</guid>
      <dc:creator>atheio</dc:creator>
      <dc:date>2022-06-16T16:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633315#M575545</link>
      <description>&lt;P&gt;Yes, the FQDN/hostname of the individual ISE Server (or a wildcard) must be in the SAN field.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI, your screenshot includes the actual DNS name of the ISE node.&amp;nbsp; You may want to blank that out for privacy.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 16:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633315#M575545</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-06-16T16:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633815#M575578</link>
      <description>&lt;P&gt;I identified the issue. The wrong cert was purchased. We ordered a basic, when we needed a wildcard, that was why "www." was getting auto-populated in the SAN field. Thank you all for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 13:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-issue/m-p/4633815#M575578</guid>
      <dc:creator>atheio</dc:creator>
      <dc:date>2022-06-17T13:51:04Z</dc:date>
    </item>
  </channel>
</rss>

