<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate Generation Failed BYOD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133117#M590154</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are new to implementing BYOD feature, currently running ISE v3.2p4 with WLC 3500 v8.10&lt;/P&gt;&lt;P&gt;Just tested with Android version 8, and every time we run the NSA and after input the user password (use for AD login and we are using PEAP to connect BYOD SSID) it shows Certificate Generation Failed.&lt;/P&gt;&lt;P&gt;I follow this link as recommended by Community but still failed.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=z0sRiffVdpg" target="_blank"&gt;ISE 2.2 Android Provisioning with EST Authentication (Certificate Generation Failed) (youtube.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And understand on the EST authentication it runs on TCP8084, I can confirm no block on the firewall but on the ISE itself the ports is not open, maybe I can start on this, how to make this port open? I did reload the ISE but still NOK.&lt;/P&gt;&lt;P&gt;Any Idea guys? I been stuck for 2weeks on this issue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ruelb2214_0-1718708647721.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221119iBDF53B91D73C192E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ruelb2214_0-1718708647721.png" alt="Ruelb2214_0-1718708647721.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2024 11:06:27 GMT</pubDate>
    <dc:creator>Ruelb2214</dc:creator>
    <dc:date>2024-06-18T11:06:27Z</dc:date>
    <item>
      <title>Certificate Generation Failed BYOD</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133117#M590154</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are new to implementing BYOD feature, currently running ISE v3.2p4 with WLC 3500 v8.10&lt;/P&gt;&lt;P&gt;Just tested with Android version 8, and every time we run the NSA and after input the user password (use for AD login and we are using PEAP to connect BYOD SSID) it shows Certificate Generation Failed.&lt;/P&gt;&lt;P&gt;I follow this link as recommended by Community but still failed.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=z0sRiffVdpg" target="_blank"&gt;ISE 2.2 Android Provisioning with EST Authentication (Certificate Generation Failed) (youtube.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And understand on the EST authentication it runs on TCP8084, I can confirm no block on the firewall but on the ISE itself the ports is not open, maybe I can start on this, how to make this port open? I did reload the ISE but still NOK.&lt;/P&gt;&lt;P&gt;Any Idea guys? I been stuck for 2weeks on this issue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ruelb2214_0-1718708647721.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221119iBDF53B91D73C192E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ruelb2214_0-1718708647721.png" alt="Ruelb2214_0-1718708647721.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 11:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133117#M590154</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2024-06-18T11:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Generation Failed BYOD</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133122#M590155</link>
      <description>&lt;P&gt;Just to add in the application status, the EST service is running&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ruelb2214_0-1718708889405.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221121i68E280E50875AB14/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ruelb2214_0-1718708889405.png" alt="Ruelb2214_0-1718708889405.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 11:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133122#M590155</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2024-06-18T11:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Generation Failed BYOD</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133408#M590174</link>
      <description>&lt;P&gt;You will not see the TCP/8084 in the 'show ports' output as the EST server is running inside an nginx container on the node. See the following guide for more information and troubleshooting on EST.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-30/217161-ca-service-and-est-service-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-30/217161-ca-service-and-est-service-on-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The BYOD flow is quite complicated and can be difficult to troubleshoot in a community forum. If you have followed the guidance on the&amp;nbsp;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-knowledge-base/android-byod-provisioning-error-quot-certificate-generation/ta-p/3733734" target="_blank"&gt;Android BYOD Provisioning Error "Certificate Generation Failed"&lt;/A&gt;&amp;nbsp;post and are still having trouble, I would suggest opening a TAC case to investigate further. These issues require much more detail to troubleshoot and, if the issue is urgent, TAC is always your best bet.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 22:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5133408#M590174</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-06-18T22:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Generation Failed BYOD</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5138734#M590374</link>
      <description>&lt;P&gt;Just to update:&lt;/P&gt;&lt;P&gt;I test on android device and collect the logs, I notice on the logs when the CNA running and installing the cert, it got the wrong cert, instead of using the portal cert it download/install the EAP/Radius cert. Do note I have cert signed by third-party CA for portal purpose only. I could understand that cert error because the fqdn of the redirection is not on the SAN of the cert (eap/radius).&lt;/P&gt;&lt;P&gt;I tried it also on Win10 it's the same issue, but when we have ISE v2.4 p7 we run on Win10 there was no issue.&lt;/P&gt;&lt;P&gt;My question is how does the CNA select a certificate? I have pending TAC open waiting for there comment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 04:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5138734#M590374</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2024-07-02T04:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Generation Failed BYOD</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5353242#M599237</link>
      <description>&lt;P&gt;Hi, did you solve the issue? We are getting the same error "&lt;SPAN&gt;Certificate generation failed"&amp;nbsp;&lt;/SPAN&gt;(ISE is version 3.3.0, Android ver. 7, 8, 14,&amp;nbsp;NSA ver. 2.4, 3.2). It is working on Apple/Windows. TAC case is opened for months with no progress at all. They are still "working hard" on it, but it seems they are "sleeping hard", as I read these old posts. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 15:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-generation-failed-byod/m-p/5353242#M599237</guid>
      <dc:creator>Lubo1</dc:creator>
      <dc:date>2025-12-08T15:48:53Z</dc:date>
    </item>
  </channel>
</rss>

