<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain wildcard certificate works on Windows 11 but not on windows in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218930#M592930</link>
    <description>&lt;P&gt;you need to generate new EAP cert. with wildcard in SAN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;contact the CA admin ask him about this point&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Sat, 02 Nov 2024 10:27:37 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-11-02T10:27:37Z</dc:date>
    <item>
      <title>Domain wildcard certificate works on Windows 11 but not on windows 10</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218523#M592902</link>
      <description>&lt;P&gt;I have a domain wildcard certificate installed on my cisco ISE cluster for client authentication.&lt;/P&gt;&lt;P&gt;I realized that windows 11 client were able to connect to the Wi-Fi but windows 10 client could not connect.&lt;/P&gt;&lt;P&gt;Please any idea what can be done to the windows 10 clients to enable them connect to the network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 11:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218523#M592902</guid>
      <dc:creator>davennykayowo</dc:creator>
      <dc:date>2024-11-01T11:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218534#M592903</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158462"&gt;@davennykayowo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Were the windows 10 clients provisioned with the certificate?&lt;/P&gt;
&lt;P&gt;Which logs do you see on the ISE when windows 10 clients try to access the wifi network? or which logs do you see on the Wireless lan controller?&lt;/P&gt;
&lt;P&gt;How is the windows 10 clients´s supplicantes configured? Are they configured to use certificate?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 11:19:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218534#M592903</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-11-01T11:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218577#M592908</link>
      <description>&lt;P&gt;I read somewhere' some win OS reject cert. If it have wildcard (*) in CN and as solution ypu need to use wildcard in SAN instead.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 13:10:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218577#M592908</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-01T13:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218654#M592918</link>
      <description>&lt;P&gt;This is the response from ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="davennykayowo_0-1730475482381.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232931iC3AF136C5E5D5C00/image-size/medium?v=v2&amp;amp;px=400" role="button" title="davennykayowo_0-1730475482381.png" alt="davennykayowo_0-1730475482381.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 15:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218654#M592918</guid>
      <dc:creator>davennykayowo</dc:creator>
      <dc:date>2024-11-01T15:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218658#M592919</link>
      <description>&lt;P&gt;I also read something like this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions&lt;BR /&gt;1. Is there anything that can be done (aside not validating the certificate) on the windows 10 clients to accept the wildcard certs&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;2. How can I change the wildcard cert to a SAN instead&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 15:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218658#M592919</guid>
      <dc:creator>davennykayowo</dc:creator>
      <dc:date>2024-11-01T15:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218661#M592920</link>
      <description>&lt;P&gt;It's a production environment, the only thing that changed was changing the certificate to wildcard instead of individual certs.&lt;/P&gt;&lt;P&gt;From the event viewer on one of the windows 10 machine, it indicated that the certificate was rejected because it's wildcard.&lt;/P&gt;&lt;P&gt;I just want to know If there's anything that can be done on the windows 10 machine to accept the wildcard cert.&lt;BR /&gt;I will be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 15:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218661#M592920</guid>
      <dc:creator>davennykayowo</dc:creator>
      <dc:date>2024-11-01T15:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218682#M592921</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158462"&gt;@davennykayowo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;It seems the list for problem with wildcard certificate is huge. I have found an old but interesting discussion here in the forum, but they are mentioning Windows Vista and 8.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-and-certificate-wildcard-support-with-microsoft-windows/td-p/3677039" target="_blank"&gt;Solved: ISE and certificate wildcard support with Microsoft Windows supplicants - does it work? - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I did not find Microsoft explicitly saying windows 10 does not support Wildcard but what I can say by experience is that here where I work, we are getting rid of wildcard certificate due security issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And there is not easy way to fix it. You need to create a new certificate on the CA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.digicert.com/kb/ssl-support/wildcard-compatibility.htm" target="_blank"&gt;Common Wildcard Compatibility Errors&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;Security Certificate Errors&lt;/H1&gt;
&lt;DIV id="mainContainer"&gt;
&lt;DIV id="mainContent" class="main-content"&gt;
&lt;DIV class="container"&gt;
&lt;H2&gt;Wildcard Compatibility Errors&lt;/H2&gt;
&lt;P&gt;Almost all servers, devices, services, and platforms work fine with wildcard certificates. However, there are a few known incompatibilities. These issues are not specific to DigiCert® certificates—they are caused by the way wildcard characters are handled.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Microsoft Office Communication Server&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not accept wildcards.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Microsoft Lync Server&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not accept wildcards.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Oracle Wallet Manager&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not accept wildcards.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Windows Mobile 5&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;devices cannot use wildcards. This is not an issue in future versions.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Microsoft Outlook&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;cannot use RPC over HTTP with a wildcard unless you change the Outlook provider to *.yourdomain.com.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Barracuda Spam Firewalls&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can only create a certificate with a name that matches the server name. Technically, you can work around this issue by naming your server in the *.domain.com format.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;LDAPS (Lightweight Directory Access Protocol)&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not support wildcards.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;I&gt;Active Directory&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not support wildcards.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;I&gt;Microsoft Exchange 2007 Service Pack 1&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.digicert.com/kb/ssl-support/exchange-2007-wildcards.htm" target="_blank"&gt;will not work with IMAP and POP services&lt;/A&gt;. This is not an issue in future versions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 01 Nov 2024 16:27:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218682#M592921</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-11-01T16:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218930#M592930</link>
      <description>&lt;P&gt;you need to generate new EAP cert. with wildcard in SAN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;contact the CA admin ask him about this point&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 10:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5218930#M592930</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-02T10:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Domain wildcard certificate works on Windows 11 but not on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5232711#M593592</link>
      <description>&lt;P&gt;This is a windows 10 vs windows 11 behaviour issue.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/windows-11-changes#updated-server-certificate-validation-behavior-in-windows-11" target="_blank"&gt;EAP - What's changed in Windows 11 | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h2"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="wildcard-certificates" class="heading-anchor"&gt;Wildcard certificates&lt;/H3&gt;
&lt;/DIV&gt;
&lt;P&gt;In Windows 11, Windows will no longer immediately reject server certificates that contain a wildcard (&lt;CODE&gt;*&lt;/CODE&gt;) in the certificate Common Name (CN). However, it's recommended that DNS name in the Subject Alternate Name (SubjectAltName/SAN) extension field is used, as Windows will ignore the CN components when checking for a DNS match if the SAN contains a DNS name choice. The SubjectAltName DNS name supports a wildcard in Windows 11, as it has on prior versions of Windows.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 03:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-wildcard-certificate-works-on-windows-11-but-not-on/m-p/5232711#M593592</guid>
      <dc:creator>edward_uc</dc:creator>
      <dc:date>2024-12-05T03:33:42Z</dc:date>
    </item>
  </channel>
</rss>

