<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Wildcard Cert issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5113646#M589565</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI&lt;BR /&gt;&lt;STRONG&gt;CSCwc64480&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2024 19:17:43 GMT</pubDate>
    <dc:creator>N3om</dc:creator>
    <dc:date>2024-05-22T19:17:43Z</dc:date>
    <item>
      <title>ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5107605#M589485</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have just re-added a wildcard cert to ISE as it was about to expire, when I now try connecting to guest wireless network I don tget to the portal page and i get a warning saying this web page at &lt;A href="https://guest.boarders.co.uk" target="_blank"&gt;https://guest.boarders.co.uk&lt;/A&gt; :8443&amp;nbsp; &amp;nbsp; &amp;nbsp;could not be loaded due to net:: err_ssl_version_or_cipher_mistmatch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aNy ideas what I might have missed please.??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 12:27:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5107605#M589485</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-05-17T12:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5110219#M589492</link>
      <description>&lt;P&gt;what certificate was there before Wild card ? or SAN ?&lt;/P&gt;
&lt;P&gt;Look at the guide lines :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;what ISE version ? if the cert is good&amp;nbsp; and try remove old cert and reload ISE and test it.&lt;/P&gt;
&lt;P&gt;check below :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 09:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5110219#M589492</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-05-19T09:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5110429#M589497</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1726559"&gt;@N3om&lt;/a&gt;&amp;nbsp;is this the error message you are seeing when you are redirected to the ISE Portal page on a guest device?&amp;nbsp; &amp;nbsp;Doesn't sound like a certificate issue, since the certificate does not dictate what version of TLS is used.&lt;/P&gt;
&lt;P&gt;Examine the new certificate anyway - does the browser manage to load it and can you verify that the new certificate is being presented to the browser?&lt;/P&gt;
&lt;P&gt;Run a tcpdump on the ISE node to see what is going wrong with the TLS exchange.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried restarting the PSN node (app stop ise, reload)?&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 21:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5110429#M589497</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-19T21:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5112428#M589540</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;I think we had hit a bug which Cisco published a while back as I went through the steps Cisco suggested and it seems to have worked.&lt;/P&gt;&lt;P&gt;1. create a self signed Cert for Guest portal&lt;/P&gt;&lt;P&gt;2. delete new wildcard cert and old if still there&lt;/P&gt;&lt;P&gt;3. reload PSN and PAN nodes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hers another question if I may, when i watch tutorials online for adding wildcard cert via CSR, in the first DNS field is e.g&lt;/P&gt;&lt;P&gt;ise.local.co.uk, then the second dns fielsd is *.local.co.uk, I havent done it like this as the last cert didnt have it I have got&lt;/P&gt;&lt;P&gt;*.boarders.co.uk&lt;/P&gt;&lt;P&gt;boaders.co.uk&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;our guest portal is actually guest.boaders.co.uk&lt;BR /&gt;&lt;BR /&gt;any idea which is the correct way please.?? and why.?????&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 20:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5112428#M589540</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-05-21T20:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5112512#M589542</link>
      <description>&lt;P&gt;Glad you found a resolution for the cert issue via the TAC.&amp;nbsp; I will keep that one in mind.&lt;/P&gt;
&lt;P&gt;As for the question of SAN fields, this is up to&lt;/P&gt;
&lt;P&gt;1) How the CA populated them (usually CA's will ensure that the Subject CN is always present somewhere in the SAN - e.g. if you submit a CSR with a Subject CN = &lt;A href="http://www.zebra.com" target="_blank"&gt;www.zebra.com&lt;/A&gt; and forget to include &lt;A href="http://www.zebra.com" target="_blank"&gt;www.zebra.com&lt;/A&gt;&amp;nbsp;in the SAN, then any good CA will add it into the SAN)&lt;/P&gt;
&lt;P&gt;2) How the browser chooses to select amongst multiple SAN entries. Perhaps there is an RFC out there that recommends/suggests the ordering, but I would think that the ordering of the SAN entries is arbitrary - as long as ONE of those entries satisfies the matching requirements - that's all that's required.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 22:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5112512#M589542</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-21T22:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5113646#M589565</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI&lt;BR /&gt;&lt;STRONG&gt;CSCwc64480&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 19:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5113646#M589565</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-05-22T19:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wildcard Cert issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5113652#M589566</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (132).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/218937i6FC8225A09C40C6C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (132).png" alt="Screenshot (132).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 19:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wildcard-cert-issue/m-p/5113652#M589566</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-22T19:24:56Z</dc:date>
    </item>
  </channel>
</rss>

