<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate warning Webauth Login Portal when Sectigo R46 cert is in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335765#M598410</link>
    <description>&lt;P&gt;Older clients won’t trust sectigo R46 since it’s not in their root store. ISE can’t re-sign or cross-sign the cert — your best bet is either use a cross-signed intermediate from Sectigo (if available) or switch to another CA with a root still trusted by legacy devices.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Oct 2025 20:22:13 GMT</pubDate>
    <dc:creator>david467</dc:creator>
    <dc:date>2025-10-03T20:22:13Z</dc:date>
    <item>
      <title>Certificate warning Webauth Login Portal when Sectigo R46 cert is used</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335759#M598407</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Unfortunately, old versions of iOS, Android, Chromebook do not include in their Trusted Root CA DB/List, the Sectigo Root R46 certificate so my Web-authentication login portal that uses a cert signed by that Sectigo Root R46 is giving me certificate warnings like untrusted website or similar.&lt;/P&gt;&lt;P&gt;We cannot change the template provided by Sectigo when signing our CSR's so every single certificate is signed by that Sectigo R46 Root.&lt;/P&gt;&lt;P&gt;We cannot have that certificate warning displayed during the Web-Authentication process, the ISE login portal must be displayed automatically for those old version devices. Any suggestion other than getting the cert from another vendor and see if it works?.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean, is there a way to modify the Cisco ISE cert and make it like a cross-signed cert so old and new devices can trust the ISE certificate for WebAuth?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;AJ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 18:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335759#M598407</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2025-10-03T18:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate warning Webauth Login Portal when Sectigo R46 cert is</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335763#M598409</link>
      <description>&lt;P&gt;You should look at getting a certificate from a new vendor if you need this to work in the short term. There is nothing you can realistically do to resolve this issue while sticking to the&amp;nbsp;&lt;SPAN&gt;R46 root&lt;/SPAN&gt;, but the problem will likely "go away" as these older devices eventually ages out.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 19:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335763#M598409</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2025-10-03T19:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate warning Webauth Login Portal when Sectigo R46 cert is</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335765#M598410</link>
      <description>&lt;P&gt;Older clients won’t trust sectigo R46 since it’s not in their root store. ISE can’t re-sign or cross-sign the cert — your best bet is either use a cross-signed intermediate from Sectigo (if available) or switch to another CA with a root still trusted by legacy devices.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 20:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-warning-webauth-login-portal-when-sectigo-r46-cert/m-p/5335765#M598410</guid>
      <dc:creator>david467</dc:creator>
      <dc:date>2025-10-03T20:22:13Z</dc:date>
    </item>
  </channel>
</rss>

