<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Actually we are not using AD, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530513#M72908</link>
    <description>&lt;P&gt;Actually we are not using AD,&amp;nbsp; clients are in workgroup environment.&lt;/P&gt;&lt;P&gt;And yes the certificate is present in the certificate store&amp;nbsp; after the users changes his win password.&lt;/P&gt;&lt;P&gt;Actually we don't get any error message on the ISE,&amp;nbsp; while the users try to connect to network, no msg displays on ISE authentication page at all.&amp;nbsp; it means the client doesnot send even any auth messages to ise as soon as he changes his win account password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 27 Sep 2014 03:55:03 GMT</pubDate>
    <dc:creator>waheedullah Bahaduri</dc:creator>
    <dc:date>2014-09-27T03:55:03Z</dc:date>
    <item>
      <title>ISE certificate-authentication stops working when chaning Windows User account password</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530509#M72904</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have certificate-based authentication through ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is, clients who have certificate installed,&amp;nbsp;when they change their local windows user account password,&amp;nbsp; after that their certificate authentication fails and they can not connect to network using their certificate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then we have to reinstall their certificates . this means each time users change their win password, we have to also reinstall their certificates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice, why it happening such ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530509#M72904</guid>
      <dc:creator>waheedullah Bahaduri</dc:creator>
      <dc:date>2019-03-11T05:03:20Z</dc:date>
    </item>
    <item>
      <title> Any instructions ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530510#M72905</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any instructions ?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 07:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530510#M72905</guid>
      <dc:creator>waheedullah Bahaduri</dc:creator>
      <dc:date>2014-09-25T07:07:15Z</dc:date>
    </item>
    <item>
      <title>Certificate authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530511#M72906</link>
      <description>&lt;P&gt;Certificate authentication and standard AD username/password are separate and should not be affecting one another. A few questions:&lt;/P&gt;&lt;P&gt;1. What happens to the certificate after the user changes the password? Is the certificate still present in the certificate store?&lt;/P&gt;&lt;P&gt;2. What is the error message that you see in ISE? Post screen shot(s) of the live authentication screen and the details page&lt;/P&gt;&lt;P&gt;3. Post screenshots of your AAA policies in ISE (authentication and authorization)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 21:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530511#M72906</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-09-25T21:08:39Z</dc:date>
    </item>
    <item>
      <title>Sounds like you are using</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530512#M72907</link>
      <description>&lt;P&gt;Sounds like you are using user certificates ? otherwise those two things should not be related at all.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2014 10:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530512#M72907</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2014-09-26T10:57:23Z</dc:date>
    </item>
    <item>
      <title>Actually we are not using AD,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530513#M72908</link>
      <description>&lt;P&gt;Actually we are not using AD,&amp;nbsp; clients are in workgroup environment.&lt;/P&gt;&lt;P&gt;And yes the certificate is present in the certificate store&amp;nbsp; after the users changes his win password.&lt;/P&gt;&lt;P&gt;Actually we don't get any error message on the ISE,&amp;nbsp; while the users try to connect to network, no msg displays on ISE authentication page at all.&amp;nbsp; it means the client doesnot send even any auth messages to ise as soon as he changes his win account password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Sep 2014 03:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530513#M72908</guid>
      <dc:creator>waheedullah Bahaduri</dc:creator>
      <dc:date>2014-09-27T03:55:03Z</dc:date>
    </item>
    <item>
      <title>Are the certs machine certs ?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530514#M72909</link>
      <description>&lt;P&gt;Are the certs machine certs ? Are you installing the cert in the machine store in windows ?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 04:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530514#M72909</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2014-09-29T04:23:46Z</dc:date>
    </item>
    <item>
      <title>Hmm, ISE should still get a</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530515#M72910</link>
      <description>&lt;P&gt;Hmm, ISE should still get a log weather or not the supplicant/client responds to the Radius challenge. So from what you are describing the client is not even starting the EAPoL process.&lt;/P&gt;&lt;P&gt;So I have a few more questions:&lt;/P&gt;&lt;P&gt;1. How are CSRs generated, who signs them and how are the certificates installed on the endpoints&lt;/P&gt;&lt;P&gt;2. Is this for wireless or wired&lt;/P&gt;&lt;P&gt;3. Please provide a screenshot of ISE's authentication and authorization policies&lt;/P&gt;&lt;P&gt;4. What is the make, model and version of the NADs that you are using&lt;/P&gt;&lt;P&gt;5. Confirm that you are trying to perform EAP-TLS based authentication&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 05:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530515#M72910</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-09-29T05:21:27Z</dc:date>
    </item>
    <item>
      <title>Hi Jan, I am not that</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530516#M72911</link>
      <description>&lt;P&gt;Hi Jan, I am not that proficient with AD/Workgroups so can you explain how changing a user password can affect a user certificate?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 05:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530516#M72911</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-09-29T05:57:24Z</dc:date>
    </item>
    <item>
      <title>Hello, CSRs are generated as</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530517#M72912</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CSRs are generated as client-machine certifcates, and are being signed by our own private CA Windows-Server. and they are importerted to clients local-user &amp;amp; Loca-Machine certificate-store.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificates are used for wireless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAD is the WLC , Version 7.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 07:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530517#M72912</guid>
      <dc:creator>waheedullah Bahaduri</dc:creator>
      <dc:date>2014-10-01T07:03:10Z</dc:date>
    </item>
    <item>
      <title>Before I can provide more</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530518#M72913</link>
      <description>&lt;P style="font-size: 14px;"&gt;Before I can provide more help I will also need:&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;1. What is the error message that you see in ISE? Post screen shot(s) of the live authentication screen and the details page&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;2.. Post screenshots of your AAA policies in ISE (authentication and authorization)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 16:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530518#M72913</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-02T16:01:42Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530519#M72914</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know this thread is from a long time ago but I was wondering if anyone could offer any assistance. We recently installed CISCO ASA devices and we are having the same issues as this. We have installed user certs for client authentication and most but not every time the user updates his windows password we get certificate validation error and the user appears to lose access to his private key although if i look on the security tab of the key the user is still the owner. The only way we can then get the client to connect again is to re-install the cert and reboot the machine. The cert is in the user personal store.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;has anyone else come across this kind of issue??&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 10:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530519#M72914</guid>
      <dc:creator>U E</dc:creator>
      <dc:date>2017-06-06T10:31:34Z</dc:date>
    </item>
    <item>
      <title>It happens with those users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530520#M72915</link>
      <description>&lt;P&gt;It happens with those users having administrative rights with thier win account profiles. Limited account users may not face such issues when changing thier win user passwords&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 13:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530520#M72915</guid>
      <dc:creator>waheedullah Bahaduri</dc:creator>
      <dc:date>2017-06-06T13:21:13Z</dc:date>
    </item>
    <item>
      <title>Hi and thanks for getting</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530521#M72916</link>
      <description>&lt;P&gt;Hi and thanks for getting back to me it is much appreciated&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The users were this is happening to are just standard domain users not admins&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you clarify exactly what you mean by administrative rights within the user account profiles&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sorry to be a pain&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 13:24:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530521#M72916</guid>
      <dc:creator>U E</dc:creator>
      <dc:date>2017-06-06T13:24:49Z</dc:date>
    </item>
    <item>
      <title>I was getting same issue with</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530522#M72917</link>
      <description>&lt;P&gt;I was getting same issue with those users whose windows account had aministrative priviledge who were in workgroup&lt;/P&gt;
&lt;P&gt;However limited users do not face with such issues even if they change thier password.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530522#M72917</guid>
      <dc:creator>waheedullah Bahaduri</dc:creator>
      <dc:date>2017-06-06T14:42:42Z</dc:date>
    </item>
    <item>
      <title>Think our issue may be a bit</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530523#M72918</link>
      <description>&lt;P&gt;Think our issue may be a bit different then as non of the users who are having the issues have administrative rights. They are all just domain users they reset the password then on next any connect login the receive the error "certificate validation error"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for getting back to me though&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 10:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-authentication-stops-working-when-chaning/m-p/2530523#M72918</guid>
      <dc:creator>U E</dc:creator>
      <dc:date>2017-06-07T10:00:28Z</dc:date>
    </item>
  </channel>
</rss>

