<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;lt;B&amp;gt;Symptom:&amp;lt;/B&amp;gt; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474682#M88227</link>
    <description>&lt;PRE style="font-family:monospace; font-size:12px; white-space:normal; white-space:-moz-pre-wrap; white-space:pre-wrap;  white-space:-pre-wrap; white-space:-o-pre-wrap; word-wrap:break-word;"&gt;
&amp;lt;B&amp;gt;Symptom:&amp;lt;/B&amp;gt;

Some endpoint devices (Windows OS)  have issues with wildcard cert when CN contains * (start) as wildcard

the PEAP authentication fails due to "12511 Unexpectedly received TLS alert message; treating as a rejection by the client"



&amp;lt;B&amp;gt;Conditions:&amp;lt;/B&amp;gt;
when the  wildcard cert  contains  * (start) as wildcard in CN 

&amp;lt;B&amp;gt;Workaround:&amp;lt;/B&amp;gt;

create wildcard with * (start)
e.g. CN= aaa.cisco.com&lt;/PRE&gt;</description>
    <pubDate>Fri, 01 Aug 2014 01:27:51 GMT</pubDate>
    <dc:creator>Saurav Lodh</dc:creator>
    <dc:date>2014-08-01T01:27:51Z</dc:date>
    <item>
      <title>ISE Single SSID BYOD - Windows Endpoint user experience</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474679#M88220</link>
      <description>&lt;P&gt;We are implementing wireless BYOD using Cisco ISE 1.2 and WLC 7.4x. We are using PEAP / MS-CHAP v2 for wireless security. We are able to on-board iOS, Adroid, and MAC OS endpoints using single SSID and Native supplicant provisiong seems to work fine with these endpoints. We are having issues with Windows clients. On Windows client, when the user selects the SSID, it is prompting for userid/password, but never gets a pop-up for server certificate. We are using a third party public wildcard certificate on ISE for HTTP/EAP authentication.&amp;nbsp; On ISE, we are getting: &lt;SPAN style="color: #ff0000;"&gt;12511 Unexpectedly received TLS alert message; treating as a rejection by the client.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474679#M88220</guid>
      <dc:creator>rchilukuri</dc:creator>
      <dc:date>2019-03-11T04:22:19Z</dc:date>
    </item>
    <item>
      <title>ISE Single SSID BYOD - Windows Endpoint user experience</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474680#M88222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems you are running into an Internal bug where PEAP/TLS authentication fails on Windows when using a Wildcard Certificate. Other devices such as Android, MAC OS etc work fine. During testing, this was found to be an issue with blank CN. Does your certificate have a blank CN field as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately the bug is not resolved yet, and still being worked on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks,&lt;/P&gt;&lt;P&gt;Aastha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 17:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474680#M88222</guid>
      <dc:creator>Aastha Chaudhary</dc:creator>
      <dc:date>2014-02-10T17:41:31Z</dc:date>
    </item>
    <item>
      <title>ISE Single SSID BYOD - Windows Endpoint user experience</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474681#M88225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" width="900"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD align="right" height="140" style="height: 105.0pt; width: 83pt;" width="110"&gt;12511&lt;/TD&gt;&lt;TD style="border-left: none; width: 83pt;" width="110"&gt;EAP&lt;/TD&gt;&lt;TD style="border-left: none; width: 188pt;" width="250"&gt;Unexpectedly&amp;nbsp;&amp;nbsp; received TLS alert message; treating as a rejection by the client&lt;/TD&gt;&lt;TD style="border-left: none; width: 240pt;" width="320"&gt;While trying to&amp;nbsp;&amp;nbsp; negotiate a TLS handshake with the client, ISE received an unexpected TLS&amp;nbsp;&amp;nbsp; alert message. This might be due to the supplicant not trusting the ISE&amp;nbsp;&amp;nbsp; server certificate for some reason. ISE treated the unexpected message as a&amp;nbsp;&amp;nbsp; sign that the client rejected the tunnel establishment.&lt;/TD&gt;&lt;TD style="border-left: none; width: 83pt;" width="110"&gt;Warn&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Feb 2014 19:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474681#M88225</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2014-02-11T19:08:27Z</dc:date>
    </item>
    <item>
      <title>&lt;B&gt;Symptom:&lt;/B&gt;</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474682#M88227</link>
      <description>&lt;PRE style="font-family:monospace; font-size:12px; white-space:normal; white-space:-moz-pre-wrap; white-space:pre-wrap;  white-space:-pre-wrap; white-space:-o-pre-wrap; word-wrap:break-word;"&gt;
&amp;lt;B&amp;gt;Symptom:&amp;lt;/B&amp;gt;

Some endpoint devices (Windows OS)  have issues with wildcard cert when CN contains * (start) as wildcard

the PEAP authentication fails due to "12511 Unexpectedly received TLS alert message; treating as a rejection by the client"



&amp;lt;B&amp;gt;Conditions:&amp;lt;/B&amp;gt;
when the  wildcard cert  contains  * (start) as wildcard in CN 

&amp;lt;B&amp;gt;Workaround:&amp;lt;/B&amp;gt;

create wildcard with * (start)
e.g. CN= aaa.cisco.com&lt;/PRE&gt;</description>
      <pubDate>Fri, 01 Aug 2014 01:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-single-ssid-byod-windows-endpoint-user-experience/m-p/2474682#M88227</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-08-01T01:27:51Z</dc:date>
    </item>
  </channel>
</rss>

