<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure client Certificate error with cisco ise posture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933390#M584383</link>
    <description>&lt;P&gt;Hi, i'm using the same certificate that i use for EAP auth, in fact, the client provisioning portal certificate is trusted in my browser, the warning only happens with the client, that's why i'm thinking that it can be a misconfiguration&lt;/P&gt;
&lt;P&gt;the only thing that i found so far on dart logs regarding certs is this:&lt;/P&gt;
&lt;P&gt;Function: LocalPolicy::GetTrustedISECertFingerprints&lt;BR /&gt;Thread Id: 0x8A0&lt;BR /&gt;File: LocalPolicy.cpp&lt;BR /&gt;Line: 83&lt;BR /&gt;Level: warn&lt;/P&gt;
&lt;P&gt;XML exception: {1, missing key 'TrustedISECertFingerprints'}.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Function: HttpConnection::initializeTrustedISECertFingerprintsVec&lt;BR /&gt;Thread Id: 0x8A0&lt;BR /&gt;File: HttpConnection.cpp&lt;BR /&gt;Line: 861&lt;BR /&gt;Level: info&lt;/P&gt;
&lt;P&gt;TrustedISECertFingerprints tag not found.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but i still don't know where i'm i wrong&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2023 13:30:03 GMT</pubDate>
    <dc:creator>jperez netics</dc:creator>
    <dc:date>2023-10-03T13:30:03Z</dc:date>
    <item>
      <title>Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4932967#M584366</link>
      <description>&lt;P&gt;i currently have an enviroment where i have a DC, with CA role, and a cisco ISE with EAP authentication and portals working just fine, but when i do posture with cisco secure client ISE posture, i get an issue with the certificate that says "Certificate is not identified for this purpose"&lt;/P&gt;
&lt;P&gt;I was searching over the internet for this problem and could not find the solution&lt;/P&gt;
&lt;P&gt;I am using the same certificate for EAP authentication, portal, and admin, the cert is from a private CA and the certificate chain is distributed over the endpoints that i'm trying to posture&lt;/P&gt;
&lt;P&gt;The ISE certificate EKU are "server authentication" and "client authentication" because it is multi purpose&lt;/P&gt;
&lt;P&gt;I don't know if i am missing a certificate attribute or an ISE configuration because it only happens on posture, the certificate is only untrusted on posture&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;only for clarification, if i disable the option "block connections to untrusted servers" in Cisco Secure Client, i can posture with the warning showing every time&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 21:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4932967#M584366</guid>
      <dc:creator>jperez netics</dc:creator>
      <dc:date>2023-10-02T21:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933100#M584368</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1362161"&gt;@jperez netics&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You need to take a look into DART file, to understand from where does this message comes. If I would need to guess, I would say it is from Client Provisioning Portal - portal responsible to push necessary software and profiles to your PC when posturing. Go there and check which certificate you are using. Error message is about certificate being untrusted, meaning it is not related to attributes (KU, EKU, and similar) but rather for domains it signs.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 06:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933100#M584368</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2023-10-03T06:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933390#M584383</link>
      <description>&lt;P&gt;Hi, i'm using the same certificate that i use for EAP auth, in fact, the client provisioning portal certificate is trusted in my browser, the warning only happens with the client, that's why i'm thinking that it can be a misconfiguration&lt;/P&gt;
&lt;P&gt;the only thing that i found so far on dart logs regarding certs is this:&lt;/P&gt;
&lt;P&gt;Function: LocalPolicy::GetTrustedISECertFingerprints&lt;BR /&gt;Thread Id: 0x8A0&lt;BR /&gt;File: LocalPolicy.cpp&lt;BR /&gt;Line: 83&lt;BR /&gt;Level: warn&lt;/P&gt;
&lt;P&gt;XML exception: {1, missing key 'TrustedISECertFingerprints'}.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Function: HttpConnection::initializeTrustedISECertFingerprintsVec&lt;BR /&gt;Thread Id: 0x8A0&lt;BR /&gt;File: HttpConnection.cpp&lt;BR /&gt;Line: 861&lt;BR /&gt;Level: info&lt;/P&gt;
&lt;P&gt;TrustedISECertFingerprints tag not found.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but i still don't know where i'm i wrong&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 13:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933390#M584383</guid>
      <dc:creator>jperez netics</dc:creator>
      <dc:date>2023-10-03T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933394#M584384</link>
      <description>&lt;P&gt;Can you check configuration of "AnyConnectLocalPolicy.xml" under "C:\ProgramData\Cisco\Cisco Secure Client\"? There is a section related to CertificateTrust, and also for allowed servers.&lt;/P&gt;
&lt;P&gt;Also, please check &lt;A href="https://community.cisco.com/t5/network-access-control/security-warning-untrusted-server-certificate-quot-anyconn-ise/td-p/4502784" target="_self"&gt;this post&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 13:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933394#M584384</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2023-10-03T13:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933494#M584390</link>
      <description>&lt;P&gt;Information Update: this only happens with Anyconnect / Secure Client Downloader with ISE posture when the Scan begins, the same certificate is trusted in any other scenario&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jpereznetics_0-1696347847437.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/198694iE4BB39FB403C75B7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jpereznetics_0-1696347847437.png" alt="jpereznetics_0-1696347847437.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 15:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933494#M584390</guid>
      <dc:creator>jperez netics</dc:creator>
      <dc:date>2023-10-03T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933567#M584392</link>
      <description>&lt;P&gt;after a series of tests, i figured out the additional certificate requirements for Posture&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For certificate trust:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Proper CN and SAN&lt;/LI&gt;
&lt;LI&gt;Proper certificate chain on the endpoint&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;For use with ISE in general&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;include the following EKU's:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Server authentication&lt;/LI&gt;
&lt;LI&gt;Client authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;And finally, for trusting in Anyconnect downloader&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;include the following KU's:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Non-repudiation&lt;/LI&gt;
&lt;LI&gt;Key encipherment&lt;/LI&gt;
&lt;LI&gt;Digital Signature&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;i figured it out after comparing the Self signed certificates from the ISE itself vs the Certificate signed by my internal CA (microsoft)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 17:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4933567#M584392</guid>
      <dc:creator>jperez netics</dc:creator>
      <dc:date>2023-10-03T17:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure client Certificate error with cisco ise posture</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4947196#M584834</link>
      <description>&lt;P&gt;a&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 02:12:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-client-certificate-error-with-cisco-ise-posture/m-p/4947196#M584834</guid>
      <dc:creator>RC0008</dc:creator>
      <dc:date>2023-10-25T02:12:21Z</dc:date>
    </item>
  </channel>
</rss>

