<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD Unknown CA when used for Active Authentication against non-AD LDAP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-unknown-ca-when-used-for-active-authentication-against-non/m-p/4271882#M1077269</link>
    <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to use the Captive Portal with a FMC/FTD deployment that is at version 6.6.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the Realm configured and downloaded the users, using the Digicert root CA as a trusted CA since the LDAP certificate is a wildcard certificate issued by Digicert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured the Identity policy and Access Control policy and I get to the point where I trigger the Captive Portal redirect and I get the user credentials prompt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I enter the credentials, the FTD appliance (not the FMC) is trying to verify/bind with the LDAP and fails the TLS negotiation with Unknown CA error (attached error info from a wireshark capture). On the LDAP side, the debugging shows the exact same error. The FTD appliance is the one issuing the Unknown CA message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone faced the same issue? Does anyone know of a way to upload Trusted CAs onto the FTD appliance? The Device Certificate section is for adding device certificates which were issued by a CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Razvan&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 20:06:49 GMT</pubDate>
    <dc:creator>Razvan A.</dc:creator>
    <dc:date>2021-01-13T20:06:49Z</dc:date>
    <item>
      <title>FTD Unknown CA when used for Active Authentication against non-AD LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unknown-ca-when-used-for-active-authentication-against-non/m-p/4271882#M1077269</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to use the Captive Portal with a FMC/FTD deployment that is at version 6.6.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the Realm configured and downloaded the users, using the Digicert root CA as a trusted CA since the LDAP certificate is a wildcard certificate issued by Digicert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured the Identity policy and Access Control policy and I get to the point where I trigger the Captive Portal redirect and I get the user credentials prompt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I enter the credentials, the FTD appliance (not the FMC) is trying to verify/bind with the LDAP and fails the TLS negotiation with Unknown CA error (attached error info from a wireshark capture). On the LDAP side, the debugging shows the exact same error. The FTD appliance is the one issuing the Unknown CA message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone faced the same issue? Does anyone know of a way to upload Trusted CAs onto the FTD appliance? The Device Certificate section is for adding device certificates which were issued by a CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Razvan&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 20:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unknown-ca-when-used-for-active-authentication-against-non/m-p/4271882#M1077269</guid>
      <dc:creator>Razvan A.</dc:creator>
      <dc:date>2021-01-13T20:06:49Z</dc:date>
    </item>
  </channel>
</rss>

