<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x User Authentication with Certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329182#M598112</link>
    <description>&lt;P&gt;This not option it steps&lt;/P&gt;
&lt;P&gt;You need two steps&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Sep 2025 06:51:40 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-09-11T06:51:40Z</dc:date>
    <item>
      <title>Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326678#M598022</link>
      <description>&lt;P&gt;Hello, we have ISE as AAA server and is configured to authenticate network users using user certificates issued by our local CA server.&amp;nbsp; Successfully authenticated users, which are AD users are placed on Corps&amp;nbsp; VLAN otherwise guest vlan. I have an issue lately, the certificates for some of the users expired and now are on the guest vlan. The problem is I cannot renew the certificates directly from the client as they cannot reach the CA, due to being on the guest. I get the error that it cannot reach the server. How do I go about such an issue. How do I renew the certificates for other users. Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 09:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326678#M598022</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-03T09:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326690#M598023</link>
      <description>&lt;P&gt;either you need to manually update the certs or make arrangement to push using GPO to end clients (so next time you will not have this issue)&lt;/P&gt;
&lt;P&gt;is the ISE acting as CA Server or you have PKI infrastructure ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 07:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326690#M598023</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-09-03T07:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326693#M598024</link>
      <description>&lt;P&gt;Under these user port config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access switchport mode vlan x&lt;/P&gt;
&lt;P&gt;Disable 802.1x under port&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After user re-new cert&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remove vlan and enable 802.1x again&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 07:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326693#M598024</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-03T07:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326699#M598025</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt;&amp;nbsp;temporarily to resolve this issue, allow expired certificates to allow the devices network access:-&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Navigate to &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authentication &amp;gt; Allowed Protocols &amp;gt; Default Network Access &lt;/STRONG&gt;(custom name) and checking the box for &lt;STRONG&gt;“Allow Authentication of expired certificates to allow certificate renewal in Authorization Policy”&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Then amend you GPOs to automatically renew certificates before the expire.&lt;/P&gt;
&lt;P&gt;Once certificates have been renewed, then disable the expired certificates.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 07:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326699#M598025</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-03T07:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326713#M598026</link>
      <description>&lt;P&gt;This good idea&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But then he never know what user have expired cert (authc failed) and user dont have expired cert&lt;/P&gt;
&lt;P&gt;Let ISE failed authc to make him know that.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 07:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326713#M598026</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-03T07:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326716#M598027</link>
      <description>&lt;P&gt;You can determine what devices do have expired certifciates, create a new authorisation rule matching on&amp;nbsp;&lt;STRONG id="yui_3_17_2_1_1756885915986_532"&gt;CERTIFICATE Is Expired True&lt;/STRONG&gt;. You can allow those devices just enough access to renew certificates. You will be able to run reports on what devices match this rule. All done centrally via ISE.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 07:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326716#M598027</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-03T07:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326717#M598028</link>
      <description>&lt;P&gt;That more better'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 07:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326717#M598028</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-03T07:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326779#M598030</link>
      <description>&lt;P&gt;We have a dedicated PKI server which is Windows and is integrated to AD&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 11:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326779#M598030</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-03T11:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326780#M598031</link>
      <description>&lt;P&gt;The environment is SDN based therefore I can see dot1x auth failures from the specific switch and also ports users are connected&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 11:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326780#M598031</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-03T11:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326794#M598034</link>
      <description>&lt;P&gt;Thank you Rob, let me try this option. GPO&amp;nbsp; to renew and auto enroll is already in place though&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 12:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5326794#M598034</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-03T12:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327244#M598048</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;,&amp;nbsp; tried following your workaround,however interestingly, I woke today with all devices on the network not able to authenticate and even reach DHCP server to get access to Internet. Unfortunately, Advantage Licence expired 19 days ago and we're in the process of renewing. I fixed it temporarily by enabling the Essential Licence after realising that it was disabled. But again despite all devices getting Internet, they are all placed on the guest. From the ISE license tiers, the Essential tier should provide basic AAA including dot1x authentication. Am trying to understand what could be the issue that all devices are on the guest, even domain joined Workstations with valid certificates and users. I would really appreciate for your input&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 18:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327244#M598048</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-04T18:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327250#M598049</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt;&amp;nbsp;What features are configured in your authorisation rules? What rules are being matched or is authentication/authorising failing? Provide a screenshot of the live log of an example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 18:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327250#M598049</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-04T18:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327252#M598050</link>
      <description>&lt;P&gt;Share live log detail&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Include steps&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Include authc&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Include authz&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let us check&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 18:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327252#M598050</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-04T18:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327358#M598052</link>
      <description>&lt;P&gt;then you should able to push GPO and also client side try GP update.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 07:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327358#M598052</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-09-05T07:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327401#M598057</link>
      <description>&lt;P&gt;Hi Rob,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to trace the issue to AD synchronization issue and therefore could not authenticate users, defaulting&amp;nbsp; them to guest. Authentication &amp;amp; Authorization policies are fine. I would however l like however to get to know how do I apply the policy that will renew the certificated as earlier stated. Seems the policy in place didn't renew the user cert after making changes here "&lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authentication &amp;gt; Allowed Protocols &amp;gt; Default Network Access&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;(custom name) and checking the box for&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;“Allow Authentication of expired certificates to allow certificate renewal in Authorization Policy”&lt;/STRONG&gt;&lt;SPAN&gt;."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 11:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327401#M598057</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-05T11:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327619#M598061</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt;&amp;nbsp;well first you need to make the changes on ISE to allow expired certificates, that will allow the computers on to the network. Once they have network connectivity&amp;nbsp;&lt;STRONG&gt;if&lt;/STRONG&gt; the GPO configuration for certificate enrollment is working, then the computers should renew their certificates.&lt;/P&gt;
&lt;P&gt;It's the windows GPO settings that will renew the certifictaes, example:-&amp;nbsp;&lt;A href="https://lostintransit.se/2024/11/07/leveraging-gpo-to-distribute-user-and-computer-certificate/" target="_blank"&gt;https://lostintransit.se/2024/11/07/leveraging-gpo-to-distribute-user-and-computer-certificate/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 19:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327619#M598061</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-05T19:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327653#M598062</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are two steps if yoh want use ISE for renew expired cert&lt;/P&gt;
&lt;P&gt;1- allow expired in allow protocol &amp;lt;&amp;lt;- this done&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2- add authz policy with condition&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="550" data-end="587"&gt;&lt;STRONG data-start="550" data-end="564"&gt;Attribute:&lt;/STRONG&gt; &lt;CODE data-start="565" data-end="585"&gt;Certificate Status&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="590" data-end="615"&gt;&lt;STRONG data-start="590" data-end="604"&gt;Condition:&lt;/STRONG&gt; &lt;CODE data-start="605" data-end="613"&gt;Equals&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="618" data-end="638"&gt;&lt;STRONG data-start="618" data-end="628"&gt;Value:&lt;/STRONG&gt; &lt;CODE data-start="629" data-end="638"&gt;Expired&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="618" data-end="638"&gt;Step 2 you missing it that so the policy use guest authz policy&amp;nbsp;&lt;/P&gt;
&lt;P data-start="618" data-end="638"&gt;Add it and everything will work.&lt;/P&gt;
&lt;P data-start="618" data-end="638"&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 20:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5327653#M598062</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-05T20:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329181#M598111</link>
      <description>&lt;P&gt;I have tried the first option but still no cert renewal requests or new renewals are reaching the CA.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 06:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329181#M598111</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-09-11T06:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329182#M598112</link>
      <description>&lt;P&gt;This not option it steps&lt;/P&gt;
&lt;P&gt;You need two steps&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 06:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329182#M598112</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-11T06:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x User Authentication with Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329188#M598113</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I have tried the first option but still no cert renewal requests or new renewals are reaching the CA.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt; if you modified the ISE to allow expired certificates, are the clients with expired certificates authenticated now and can they access the network?&lt;/P&gt;
&lt;P&gt;If they have network access then the latest problem doesn't seem like an ISE problem. Has the client received the GPO with the correct settings to renew the certificates? Refresh the GPO on the client computers if needs be. Have you tried manually renewing certificates to see if that works, if that works that would imply a problem with the GPO settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 07:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-user-authentication-with-certificates/m-p/5329188#M598113</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-11T07:05:43Z</dc:date>
    </item>
  </channel>
</rss>

