<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OCSP certificate Chain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ocsp-certificate-chain/m-p/5367832#M599729</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/347992"&gt;@craiglebutt&lt;/a&gt;&amp;nbsp;Can you confirm that&amp;nbsp;&lt;STRONG&gt;OCSP Client Profile&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Certificate Status Validation&amp;nbsp;&lt;/STRONG&gt;steps have been properly configured? Use following document as a guide.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Within same document, you'll find instructions on how to enable runtime-aaa debugging and get the outputs from&lt;STRONG&gt;&amp;nbsp;prrt-server.log&lt;/STRONG&gt;, as well as perform packet capture. Post the logs and packet capture, this would help to identify the root cause. Ensure to enable debug logging for a limited time windows, as it has impact on ISE performance:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222150-configure-eap-tls-authentication-with-oc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222150-configure-eap-tls-authentication-with-oc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Feb 2026 10:11:34 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2026-02-05T10:11:34Z</dc:date>
    <item>
      <title>OCSP certificate Chain</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-certificate-chain/m-p/5367825#M599727</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Have 6 Nodes 2 PAN, 4 PSN, the OCSP certificate has an issue with the chain on the first responder, in this case call int PAN2.&lt;/P&gt;&lt;P&gt;PAN2 chain is in complete.&lt;/P&gt;&lt;P&gt;I'm guessing that the other nodes OCSP Responder looks at the first PAN but their certificates don't match.&lt;/P&gt;&lt;P&gt;5 of the nodes have the same chain.&lt;/P&gt;&lt;P&gt;So when trying to onboard it doesn't work.&lt;/P&gt;&lt;P&gt;Have logged a call with TAC, over a week ago, but they are making me swear.&lt;/P&gt;&lt;P&gt;Not sure how to fix this.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 09:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-certificate-chain/m-p/5367825#M599727</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2026-02-05T09:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: OCSP certificate Chain</title>
      <link>https://community.cisco.com/t5/network-access-control/ocsp-certificate-chain/m-p/5367832#M599729</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/347992"&gt;@craiglebutt&lt;/a&gt;&amp;nbsp;Can you confirm that&amp;nbsp;&lt;STRONG&gt;OCSP Client Profile&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Certificate Status Validation&amp;nbsp;&lt;/STRONG&gt;steps have been properly configured? Use following document as a guide.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Within same document, you'll find instructions on how to enable runtime-aaa debugging and get the outputs from&lt;STRONG&gt;&amp;nbsp;prrt-server.log&lt;/STRONG&gt;, as well as perform packet capture. Post the logs and packet capture, this would help to identify the root cause. Ensure to enable debug logging for a limited time windows, as it has impact on ISE performance:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222150-configure-eap-tls-authentication-with-oc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222150-configure-eap-tls-authentication-with-oc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 10:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ocsp-certificate-chain/m-p/5367832#M599729</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-02-05T10:11:34Z</dc:date>
    </item>
  </channel>
</rss>

