<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE PIC Integration with AD, FMC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4660372#M576418</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699" target="_blank"&gt;&lt;FONT&gt;@haroungh&lt;/FONT&gt;&lt;/A&gt;&lt;FONT&gt;&lt;SPAN&gt;&amp;nbsp; Were you able to solve the problem for the integration? I have&amp;nbsp;&amp;nbsp;the same error message&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2022 15:00:11 GMT</pubDate>
    <dc:creator>Carces</dc:creator>
    <dc:date>2022-07-29T15:00:11Z</dc:date>
    <item>
      <title>ISE PIC Integration with AD, FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4494023#M570731</link>
      <description>&lt;P&gt;&amp;nbsp;Hi Dears,&lt;/P&gt;&lt;P&gt;i am doing ise-pic lab and i got the follwing error when i&amp;nbsp; have tried to enable pxgrid service in admin cert, admin cert&amp;nbsp; is signed by CA&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pxgrid-service.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/135956i87BF346BDD4ED830/image-size/large?v=v2&amp;amp;px=999" role="button" title="pxgrid-service.png" alt="pxgrid-service.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 07:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4494023#M570731</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2021-10-28T07:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PIC Integration with AD, FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4494081#M570732</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699"&gt;@GHOZLANE Haroun&lt;/a&gt; you cannot simply bind any certificate to the pxgrid service, the certificate in use must have a certificate &lt;STRONG&gt;with both server and client extended key usages (EKU’s)&lt;/STRONG&gt;. The admin certificate does not have both of these EKUs, so you will need to create a certificate specifically used for pxgrid. More information:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploying-certificates-with-pxgrid-ca-signed-ise-pxgrid/ta-p/3626277" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/how-to-deploying-certificates-with-pxgrid-ca-signed-ise-pxgrid/ta-p/3626277&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2018/08/25/cisco-ise-pxgrid-integration-with-firepower/" target="_blank" rel="noopener"&gt;https://integratingit.wordpress.com/2018/08/25/cisco-ise-pxgrid-integration-with-firepower/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/global/on-demand-library.html?search=ise&amp;amp;search.event=ciscolive2021&amp;amp;search.event=ciscoliveus2020&amp;amp;search=ise#/session/1573153556309001Jgr6" target="_blank"&gt;https://www.ciscolive.com/global/on-demand-library.html?search=ise&amp;amp;search.event=ciscolive2021&amp;amp;search.event=ciscoliveus2020&amp;amp;search=ise#/session/1573153556309001Jgr6&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 09:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4494081#M570732</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-10-28T09:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PIC Integration with AD, FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4494142#M570740</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;thanks in advance for your support,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;actually i am using&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;ise-pic as CA server and i have generated fmc identity certificate and key after that i have uploaded the ise ISE CA, sub, to trust certs and uploaded as well fmc identity cert with key to internal cert.&lt;/P&gt;&lt;P&gt;when i&amp;nbsp; have tried to joing tmc&amp;nbsp; to ise and&amp;nbsp; it is failed again, take a look bellow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE-test failed.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/135966iEE10A2D6AA5F4375/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE-test failed.PNG" alt="ISE-test failed.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Primary host:&lt;BR /&gt;[INFO]: PXGrid v2 is enabled&lt;BR /&gt;[ERROR]: Failed to contact pxGrid node at '192.168.0.250': Server returned 401: Unauthorized&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Secondary host:&lt;BR /&gt;[INFO]: PXGrid v2 is enabled&lt;BR /&gt;[ERROR]: HttpsStringRequest on_handshake error: 337047686: certificate verify failed&lt;BR /&gt;[ERROR]: HttpsStringRequest SSL error: 2021-10-28 11:35:03(GMT): Starting SSL Handshake, SSL state:before SSL initialization&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:before SSL initialization&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:SSLv3/TLS read server hello&lt;BR /&gt;2021-10-28 11:35:03(GMT): Entering OpenSSL verify callback, preverified:0, error: self signed certificate in certificate chain, error depth: 3, current_cert: Certificate with Serial Number '0x29DC468856CB4C4CA097BA9FC8CE50AF', issued by 'CN = Certificate Services Root CA - ise-pic-01', to 'CN = Certificate Services Root CA - ise-pic-01'&lt;BR /&gt;2021-10-28 11:35:03(GMT): Rejecting this certificate presented by foreign server: Certificate with Serial Number '0x0CC3C225409C4914ACCFF91E18550D9A', issued by 'CN = Certificate Services Endpoint Sub CA - ise-pic-02', to 'OU = Certificate Services System Certificate, CN = ise-pic-02.cisco.corp'&lt;BR /&gt;...because SSL negotiation encountered error: self signed certificate in certificate chain&lt;BR /&gt;...while validating this entry in the certificate chain: Certificate with Serial Number '0x29DC468856CB4C4CA097BA9FC8CE50AF', issued by 'CN = Certificate Services Root CA - ise-pic-01', to 'CN = Certificate Services Root CA - ise-pic-01'&lt;BR /&gt;2021-10-28 11:35:03(GMT): Sending SSL alert:unknown CA&lt;BR /&gt;2021-10-28 11:35:03(GMT): SSL State:error&lt;BR /&gt;[ERROR]: Failed to contact pxGrid node at '192.168.0.251': Handshake error to 192.168.0.251:8910&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 11:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4494142#M570740</guid>
      <dc:creator>GHOZLANE Haroun</dc:creator>
      <dc:date>2021-10-28T11:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PIC Integration with AD, FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4660372#M576418</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/635699" target="_blank"&gt;&lt;FONT&gt;@haroungh&lt;/FONT&gt;&lt;/A&gt;&lt;FONT&gt;&lt;SPAN&gt;&amp;nbsp; Were you able to solve the problem for the integration? I have&amp;nbsp;&amp;nbsp;the same error message&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 15:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4660372#M576418</guid>
      <dc:creator>Carces</dc:creator>
      <dc:date>2022-07-29T15:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE PIC Integration with AD, FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4965138#M585370</link>
      <description>&lt;P&gt;Anyone have a solution for @haroungh problem. I am getting the same error that is shown above on the secondary host:&lt;/P&gt;&lt;P&gt;[INFO]: PXGrid v2 is enabled&lt;BR /&gt;[ERROR]: HttpsStringRequest on_handshake error: 337047686: certificate verify failed&lt;BR /&gt;[ERROR]: HttpsStringRequest SSL error: 2021-10-28 11:35:03(GMT): Starting SSL Handshake, SSL state:before SSL initialization&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 16:51:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-integration-with-ad-fmc/m-p/4965138#M585370</guid>
      <dc:creator>mbargers</dc:creator>
      <dc:date>2023-11-23T16:51:07Z</dc:date>
    </item>
  </channel>
</rss>

