<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5120675#M589724</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/1638370/when-will-microsoft-azure-tls-issuer-be-updated-(e" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/1638370/when-will-microsoft-azure-tls-issuer-be-updated-(e&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Scroll down to the &lt;FONT color="#008000"&gt;&lt;EM&gt;Accepted Answer&lt;/EM&gt;&lt;/FONT&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2024 13:45:40 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2024-05-30T13:45:40Z</dc:date>
    <item>
      <title>Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5120532#M589718</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;We have these Azure certificates installed on a Cisco ISE server, to support the MDM integration:&lt;BR /&gt;Microsoft Azure TLS Issuing CA 01&lt;BR /&gt;Microsoft Azure TLS Issuing CA 02&lt;BR /&gt;Microsoft Azure TLS Issuing CA 05&lt;BR /&gt;Microsoft Azure TLS Issuing CA 06&lt;/P&gt;
&lt;P&gt;ISE is reporting that these certificates will expire in 32 days. I've tried to locate the new certificates but without success.&amp;nbsp;&lt;BR /&gt;Anyone else has happened?? Would you know of any solution?&lt;/P&gt;
&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 11:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5120532#M589718</guid>
      <dc:creator>Ariel_DF</dc:creator>
      <dc:date>2024-05-30T11:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5120675#M589724</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/1638370/when-will-microsoft-azure-tls-issuer-be-updated-(e" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/1638370/when-will-microsoft-azure-tls-issuer-be-updated-(e&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Scroll down to the &lt;FONT color="#008000"&gt;&lt;EM&gt;Accepted Answer&lt;/EM&gt;&lt;/FONT&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 13:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5120675#M589724</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-05-30T13:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5121735#M589748</link>
      <description>&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/t5/azure-storage-blog/azure-storage-tls-changes-intermediate-certificate-renewals/ba-p/3929149" target="_blank"&gt;https://techcommunity.microsoft.com/t5/azure-storage-blog/azure-storage-tls-changes-intermediate-certificate-renewals/ba-p/3929149&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 09:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5121735#M589748</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-05-31T09:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5123190#M589790</link>
      <description>&lt;P&gt;Thanks for the response, I'm going to try to load those certificates to see if everything works OK.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 07:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5123190#M589790</guid>
      <dc:creator>Ariel_DF</dc:creator>
      <dc:date>2024-06-03T07:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5125312#M589848</link>
      <description>&lt;P&gt;Actually, an update on this... as per the most recent updates to&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/intune-customer-success/intune-certificate-updates-action-may-be-required-for-continued/ba-p/1839655" target="_blank" rel="noopener"&gt;this MS document&lt;/A&gt;, the certificate rotation for the API endpoints used for the Compliance Retrieval (NAC 2.0) API have resulted in ISE only needing to trust the DigiCert Global Root G2 CA certificate for the MDM lookups to work.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Network Access Control (NAC) note&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For all Network Access Control (NAC) scenarios, when using a 3&lt;SUP&gt;rd&lt;/SUP&gt;&amp;nbsp;party provider such as Cisco, please be sure your NAC provider has validated their root CA config. They should have how to do this documented, but in case they don’t:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://cacerts.digicert.com/DigiCertGlobalRootG2.crt.pem" target="_self" rel="nofollow noopener noreferrer"&gt;Add&amp;nbsp;DigiCert Global Root G2&amp;nbsp;to their trusted CA store&lt;/A&gt;.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;For some providers, they many need to validate the configuration and update as needed.&lt;/LI&gt;
&lt;LI&gt;Confirm your network can receive traffic so that the configuration can be pushed down to individual ISE boxes.&lt;/LI&gt;
&lt;LI&gt;For some providers note that it can take time for updates to be distributed."&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;My guess is that MS fixed something in the way the certificate signing or chain was done in the past.&lt;/P&gt;
&lt;P&gt;I removed all of the MS TLS and MS RSA TLS certs from my ISE instance and the Intune MDM lookups still work as expected. Only if I delete the DigiCert Global Root G2 CA certificate, can I make the lookups fail. This is actually how one would expect the trust to properly work.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 22:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5125312#M589848</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-06-04T22:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5125569#M589858</link>
      <description>&lt;P&gt;Hello Greg,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had seen this a few days ago, but I had doubts because of what it says in this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/t5/azure-storage-blog/azure-storage-tls-changes-intermediate-certificate-renewals/ba-p/3929149" target="_blank"&gt;https://techcommunity.microsoft.com/t5/azure-storage-blog/azure-storage-tls-changes-intermediate-certificate-renewals/ba-p/3929149&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We have yet to define a work window outside of business hours to do this, but what you mentioned has been of great help to me.&lt;/P&gt;
&lt;P&gt;Thanks!!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 08:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5125569#M589858</guid>
      <dc:creator>Ariel_DF</dc:creator>
      <dc:date>2024-06-05T08:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5134452#M590206</link>
      <description>&lt;P&gt;Hi, I remember settring these certs up agaes ago, to clarify this is for just the MDM part for ISE?&amp;nbsp; If ISE is not carrying out the MDM, we don't need to bothere about this?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 07:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5134452#M590206</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2024-06-21T07:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure TLS Issuing CA certificate expire in Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5134761#M590217</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/347992"&gt;@craiglebutt&lt;/a&gt;... correct. Also, I believe the Digicert Global Root G2 CA cert is installed in the Trust Store by default in more recent versions of ISE as it likely signs other public certs as well.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 22:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-azure-tls-issuing-ca-certificate-expire-in-cisco-ise/m-p/5134761#M590217</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-06-21T22:55:10Z</dc:date>
    </item>
  </channel>
</rss>

