<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OCSP - response signature verification failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248618#M594277</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jagermeister_0-1737119408449.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237808i0E35F5D0948BA944/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jagermeister_0-1737119408449.png" alt="Jagermeister_0-1737119408449.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Nothing special, I try to validate it against my OCSP profile that is looking at the OCSP URL from the AIA in the certificate. Also tried to set the server manually but doesn't make a difference.&lt;/P&gt;&lt;P&gt;OCSP profile:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jagermeister_1-1737119483256.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237809i96E89B0692AEDC4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jagermeister_1-1737119483256.png" alt="Jagermeister_1-1737119483256.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jan 2025 13:11:31 GMT</pubDate>
    <dc:creator>Jagermeister</dc:creator>
    <dc:date>2025-01-17T13:11:31Z</dc:date>
    <item>
      <title>OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248595#M594273</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured my ISE setup to validate certificates against a external OCSP responder but I do not get it to work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 802.1X certificates that my supplicants are using are issued by the external CA and my ISE setup has this certificate chain imported as&amp;nbsp; trusted certificates.&amp;nbsp; I've configured a OCSP profile that is using the OCSP URLs that are specified in the AIA of the cert. As i wish, the validation of the response certificate is enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, in my live log i'm seeing the following:&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Take OCSP servers list from AIA extension of client certificate - certificate for &amp;lt;cert name&amp;gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12989&lt;/TD&gt;&lt;TD&gt;Sent an OCSP request to the next OCSP server in the list - External OCSP Server&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12567&lt;/TD&gt;&lt;TD&gt;OCSP server response signature verification failed - certificate for &amp;lt;cert name&amp;gt;&lt;/TD&gt;&lt;TD&gt;261&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12552&lt;/TD&gt;&lt;TD&gt;Conversation with OCSP server ended with failure - certificate for &amp;lt;cert name&amp;gt;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Looking into the prrt-server.log isn't revealing much either;&amp;nbsp;&lt;/P&gt;&lt;P&gt;,0x7f787ae98700,NIL-CONTEXT,Crypto::Result=0, Crypto.OcspClient::performRequest - Response signature verification failed, result 0, error error:27069076:OCSP routines:OCSP_b&lt;/P&gt;&lt;P&gt;I've tried to validate the same cert on another device against the external OCSP responder and then the response is accepted, so it seems that only my ISE setup is not able to validate the response signature for some reason.&amp;nbsp; Decided to make a TCP dump on the PSN and in OCSP response it says the cert status is good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I find more detailed information about why ISE thinks the response signature is invalid?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248595#M594273</guid>
      <dc:creator>Jagermeister</dc:creator>
      <dc:date>2025-01-17T12:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248601#M594275</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="images (4).jpeg" style="width: 878px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237802iBFA5D0FDFB80CCFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="images (4).jpeg" alt="images (4).jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; how you config these options?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248601#M594275</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-17T12:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248618#M594277</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jagermeister_0-1737119408449.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237808i0E35F5D0948BA944/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jagermeister_0-1737119408449.png" alt="Jagermeister_0-1737119408449.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Nothing special, I try to validate it against my OCSP profile that is looking at the OCSP URL from the AIA in the certificate. Also tried to set the server manually but doesn't make a difference.&lt;/P&gt;&lt;P&gt;OCSP profile:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jagermeister_1-1737119483256.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237809i96E89B0692AEDC4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jagermeister_1-1737119483256.png" alt="Jagermeister_1-1737119483256.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 13:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248618#M594277</guid>
      <dc:creator>Jagermeister</dc:creator>
      <dc:date>2025-01-17T13:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248961#M594287</link>
      <description>&lt;P&gt;Could you please try to unckeck the "Validate Response Signature" tick box and see if that makes any difference? from the logs you shared it does seem that ISE can't validate the OCSP response from the server. I know you mentioned that you already imported the OCSP certificates chain, but I would double check this and also I would make sure that those certs are not expired. Alternatively it could be something else in the OCSP response that ISE can't validate for some reason. What version of ISE are you running?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 13:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248961#M594287</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-18T13:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248974#M594291</link>
      <description>&lt;P&gt;disable Nonce only&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that it&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 14:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5248974#M594291</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-18T14:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5249312#M594300</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1797167"&gt;@Jagermeister&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;in &lt;STRONG&gt;ISE&lt;/STRONG&gt;, the &lt;STRONG&gt;Components&lt;/STRONG&gt;&amp;nbsp;that are responsible to add info to the &lt;STRONG&gt;prrt-server.log&lt;/STRONG&gt; file are:&lt;/P&gt;
&lt;UL class="lia-align-justify"&gt;
&lt;LI class="lia-align-justify"&gt;runtime-AAA&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;runtime-config&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;runtime-GRPC&lt;/LI&gt;
&lt;LI class="lia-align-justify"&gt;runtime-logging&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify"&gt;The &lt;U&gt;default&lt;/U&gt; &lt;STRONG&gt;Log Level&lt;/STRONG&gt; of &lt;STRONG&gt;ALL&lt;/STRONG&gt; these &lt;STRONG&gt;Components&lt;/STRONG&gt; are &lt;STRONG&gt;WARN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Try to &lt;U&gt;increase&lt;/U&gt; the &lt;STRONG&gt;Log Level&lt;/STRONG&gt; to get more info about your issue:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;In &lt;STRONG&gt;Operations &amp;gt; Troubleshoot &amp;gt; Debug Wizard &amp;gt; Debug Log Configuration &amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;Node&lt;/STRONG&gt; :&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Debug Wizard.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237918i1A6FC1436DF2FBF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Debug Wizard.png" alt="Debug Wizard.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 23:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5249312#M594300</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-19T23:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5249319#M594301</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1797167"&gt;@Jagermeister&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;also take a look at:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj32472" target="_blank" rel="noopener"&gt;CSCwj32472 Internal OCSP responder could not work with default configuration&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="CSCwj32472.png" style="width: 615px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237919i37EDC350A2A3A114/image-size/large?v=v2&amp;amp;px=999" role="button" title="CSCwj32472.png" alt="CSCwj32472.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi51182" target="_blank" rel="noopener"&gt;CSCwi51182 ISE as OCSP client Needs More Tolerable for Current Time Differences from those of OCSP responders&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="CSCwi51182.png" style="width: 878px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237920iC05650D78CF4C125/image-size/large?v=v2&amp;amp;px=999" role="button" title="CSCwi51182.png" alt="CSCwi51182.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 00:05:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5249319#M594301</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-20T00:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP - response signature verification failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5256517#M594755</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;said, try to disable "&lt;SPAN&gt;Validate Response Signature&lt;/SPAN&gt;" as that worked for me. In my case, Sectigo enterprise OCSP repsponder does not include the cert in the payload and that's why ISE keeps returning "Unknown", but if you check the cert by using a Linux box and command line, you will see the real response from the OCSP responder.&lt;/P&gt;
&lt;P&gt;It has non sense why Cisco ISE keeps enabling that by default when including the Certificate in the payload is an optional feature in the RFC.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 12:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-response-signature-verification-failed/m-p/5256517#M594755</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2025-02-04T12:33:37Z</dc:date>
    </item>
  </channel>
</rss>

