<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CISCO ISE DEPLOYMENT in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649085#M74429</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have configured cisco ise for Web_Auth_Redirection, Everything is working perfectly but I am having a lot of complains from users &amp;nbsp;due to the certificate not been trusted.&amp;nbsp;I understand that redirection by default is through https how can i solve this so that users are not prompted for certificate.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;can I change redirection portal to be http instead of https&lt;/LI&gt;&lt;LI&gt;can I install a certificate in the ise server that will be trusted by the clients&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:28:03 GMT</pubDate>
    <dc:creator>kennedymacharia</dc:creator>
    <dc:date>2019-03-11T05:28:03Z</dc:date>
    <item>
      <title>CISCO ISE DEPLOYMENT</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649085#M74429</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have configured cisco ise for Web_Auth_Redirection, Everything is working perfectly but I am having a lot of complains from users &amp;nbsp;due to the certificate not been trusted.&amp;nbsp;I understand that redirection by default is through https how can i solve this so that users are not prompted for certificate.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;can I change redirection portal to be http instead of https&lt;/LI&gt;&lt;LI&gt;can I install a certificate in the ise server that will be trusted by the clients&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649085#M74429</guid>
      <dc:creator>kennedymacharia</dc:creator>
      <dc:date>2019-03-11T05:28:03Z</dc:date>
    </item>
    <item>
      <title>My answers below:</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649086#M74430</link>
      <description>&lt;P&gt;My answers below:&lt;/P&gt;
&lt;UL style="margin-top: 15px; margin-bottom: 0px; font-size: 14.3999996185303px;"&gt;&lt;LI style="margin: 5px 0px;"&gt;
&lt;PRE&gt;
can I change redirection portal to be http instead of https&lt;/PRE&gt;
&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="margin: 5px 0px;"&gt;NS: No, this cannot be changed and you would not want to change it as username/passwords would be transmitted in plain-text&lt;/P&gt;
&lt;UL style="margin-top: 15px; margin-bottom: 0px; font-size: 14.3999996185303px;"&gt;&lt;LI style="margin: 5px 0px;"&gt;
&lt;PRE&gt;
can I install a certificate in the ise server that will be trusted by the clients&lt;/PRE&gt;
&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="margin: 5px 0px;"&gt;NS: Yes, you can get a certificate from a well known CA like VeriSign or GoDaddy and that way you would avoid the certificate errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2015 01:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649086#M74430</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-20T01:06:07Z</dc:date>
    </item>
    <item>
      <title>Gert, it may not help even if</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649087#M74433</link>
      <description>&lt;P&gt;Gert, it may not help even if you get proper cert for all NADs. Whether switch certificate is valid or not is another matter, the fact that the CN of the switch certificate does not match the original host name of the requested URL will force the browser to prompt the user every time.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2015 04:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649087#M74433</guid>
      <dc:creator>manjeets</dc:creator>
      <dc:date>2015-02-20T04:08:59Z</dc:date>
    </item>
    <item>
      <title>Hi Manjeet, this is a good</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649088#M74436</link>
      <description>&lt;P&gt;Hi Manjeet, this is a good point but it will only apply if using LWA (local web auth) and not CWA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2015 16:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-deployment/m-p/2649088#M74436</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-20T16:30:11Z</dc:date>
    </item>
  </channel>
</rss>

