<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DigiCert with Guest Portal - Not Trusted? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726763#M578458</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ISE v2.7&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I just uploaded a new wildcard DigiCert certificate to ISE with the Role of Guest Portal. I uploaded the new wildcard cert + the private key that my manager gave me. I checked the Allow wildcard certs checkbox and everything appeared to update just fine.&lt;/P&gt;&lt;P&gt;So I then took my Android cell and connected to our Guest Wi-Fi. When I got redirected to the login page, I got the message: &lt;EM&gt;"The network you're trying to join has security issues."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When I click View Certificate in the browser window on my cell, it shows the portal login url, and says "&lt;EM&gt;This certificate isn't from a trusted authority"&lt;/EM&gt;. It shows &lt;STRONG&gt;Issued to:&lt;/STRONG&gt; CN: *.mycompany.com and &lt;STRONG&gt;Issued by:&lt;/STRONG&gt; DigiCertTLS RSA &lt;A href="mailto:SHA@%^" target="_blank"&gt;SHA@%^&lt;/A&gt; 2020 CA1.&lt;/P&gt;&lt;P&gt;Why wouldn't DigiCert be considered a Trusted Authority? I'm confused...&lt;/P&gt;&lt;P&gt;Thanks in Advance,&lt;BR /&gt;Matt&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 17:37:52 GMT</pubDate>
    <dc:creator>Matthew Martin</dc:creator>
    <dc:date>2022-11-23T17:37:52Z</dc:date>
    <item>
      <title>DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726763#M578458</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ISE v2.7&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I just uploaded a new wildcard DigiCert certificate to ISE with the Role of Guest Portal. I uploaded the new wildcard cert + the private key that my manager gave me. I checked the Allow wildcard certs checkbox and everything appeared to update just fine.&lt;/P&gt;&lt;P&gt;So I then took my Android cell and connected to our Guest Wi-Fi. When I got redirected to the login page, I got the message: &lt;EM&gt;"The network you're trying to join has security issues."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When I click View Certificate in the browser window on my cell, it shows the portal login url, and says "&lt;EM&gt;This certificate isn't from a trusted authority"&lt;/EM&gt;. It shows &lt;STRONG&gt;Issued to:&lt;/STRONG&gt; CN: *.mycompany.com and &lt;STRONG&gt;Issued by:&lt;/STRONG&gt; DigiCertTLS RSA &lt;A href="mailto:SHA@%^" target="_blank"&gt;SHA@%^&lt;/A&gt; 2020 CA1.&lt;/P&gt;&lt;P&gt;Why wouldn't DigiCert be considered a Trusted Authority? I'm confused...&lt;/P&gt;&lt;P&gt;Thanks in Advance,&lt;BR /&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 17:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726763#M578458</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-11-23T17:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726771#M578459</link>
      <description>&lt;P&gt;how is your URL redirect FQDN&lt;/P&gt;
&lt;P&gt;is this example : guestportal.mycompany.com ? or IP ?&lt;/P&gt;
&lt;P&gt;do you have DNS entry guestportal.mycompany.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note : how about try other device ..part of testing ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 17:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726771#M578459</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-23T17:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726784#M578460</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;We have it setup to use Hostname, i.e.&amp;nbsp;&amp;nbsp; ise-location1.mycompany.com&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewMartin_0-1669226342309.png" style="width: 580px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/168855i3FFFC89A2D419126/image-dimensions/580x390?v=v2" width="580" height="390" role="button" title="MatthewMartin_0-1669226342309.png" alt="MatthewMartin_0-1669226342309.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 18:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726784#M578460</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-11-23T18:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726817#M578461</link>
      <description>&lt;P&gt;Hi Mathew,&lt;/P&gt;
&lt;P&gt;I assume you have installed Root and Intermediate CA certificates under Trusted Certificates?&lt;/P&gt;
&lt;P&gt;Which version exactly are you running? If it is v2.7 under patch 5, you might be hitting &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu84184" target="_self"&gt;CSCvu84184&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 18:55:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726817#M578461</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-23T18:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726819#M578462</link>
      <description>&lt;P&gt;So the Cert from DigiCert came with the Wildcard cert and a Root Cert. When I looked at the Root cert it appears to be the same as the existing DigiCert Root Cert that's already uploaded to ISE...&lt;/P&gt;&lt;P&gt;If I try to upload the Root cert that I received with the new wildcard cert, would it give me an error/warning if that exact same cert already exists?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 19:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726819#M578462</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-11-23T19:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726833#M578463</link>
      <description>&lt;P&gt;don’t think thats the issue here, if the root cert was not in trusted cert store, it wont even let to install wildcard cert and private key.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;review this link :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ios-wireless-users-being-prompted-to-trust-public-certificate/td-p/3820678" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ios-wireless-users-being-prompted-to-trust-public-certificate/td-p/3820678&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 19:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726833#M578463</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-11-23T19:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726853#M578464</link>
      <description>&lt;P&gt;Ok gotcha, thanks for the reply. That part makes sense...&lt;/P&gt;&lt;P&gt;From the link, I know they're specifically talking about iOS and I'm trying on an Android. But, sounds like it could be the same issue... Since I do not get the message on a Windows PC, should I assume this is just something with iOS and Android devices, and there's not really a "fix" per-say?&lt;/P&gt;&lt;P&gt;I know it also mentioned something about the Cert having a CRL list. Not really familiar with what that is. Is there a way to check if our Cert has a Certificate Revocation List?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 19:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726853#M578464</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-11-23T19:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726859#M578465</link>
      <description>&lt;P&gt;If you try to upload already existing cert, yes, it would warn you that there is a cert with same private/public key already existing.&lt;/P&gt;
&lt;P&gt;I don't think it is the issue that &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325330"&gt;@Ambuj M&lt;/a&gt; mentioned, because over there, EAP is in use, while you are using CWA with Guest portal, so different principles are in use.&lt;/P&gt;
&lt;P&gt;What is your exact ISE version? As I mentioned, there is a known bug in which ISE is not sending entire CA chain with certificate with Guest portals.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 20:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726859#M578465</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-23T20:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726860#M578466</link>
      <description>&lt;P&gt;We are running:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Version: 2.7.0.356&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Patch Information: 3&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 23 Nov 2022 20:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726860#M578466</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-11-23T20:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726865#M578467</link>
      <description>&lt;P&gt;&lt;SPAN&gt;open the public cert, details, you would see crl distribution list field.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;it may be the bug mentioned by&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330320"&gt;@Milos_Jovanovic&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;on a separate note i would think either peap or cwa, the crl issue will apply in both cases since the client need to validate ise cert in both cases, is that not right ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;when you accept certificate once, and delete mac and get redirected again, does it prompt the cert error again ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 20:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726865#M578467</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-11-23T20:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726872#M578468</link>
      <description>&lt;P&gt;In that case, most likely you are hitting &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu84184" target="_self" rel="nofollow noreferrer"&gt;CSCvu84184&amp;nbsp;&lt;/A&gt;which is solved in v2.7 patch 5. I would recommend to apply latest patch, and then to repeat testing.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 20:36:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4726872#M578468</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-23T20:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4729252#M578526</link>
      <description>&lt;P&gt;Thanks for the reply Milos.&lt;/P&gt;&lt;P&gt;I'm pretty sure the answer is yes. But, when installing patches, are they cumulative, i.e. would I just need the newest patch?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 16:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4729252#M578526</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2022-11-28T16:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4729329#M578528</link>
      <description>&lt;P&gt;Yes, patches are cumulative, and you only need to install latest one.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 19:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4729329#M578528</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-28T19:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert with Guest Portal - Not Trusted?</title>
      <link>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4730211#M578560</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - As already noted go for the latest in the 2.7 train because patches are&lt;STRONG&gt; &lt;FONT color="#008000"&gt;cumulative&lt;/FONT&gt;&lt;/STRONG&gt; avoid &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;p&lt;U&gt;5&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt; because of :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa00729" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa00729&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 09:22:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/digicert-with-guest-portal-not-trusted/m-p/4730211#M578560</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-11-30T09:22:15Z</dc:date>
    </item>
  </channel>
</rss>

