<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error to validate a pxGrid certificate in FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162682#M1115189</link>
    <description>&lt;P&gt;When you generated the certificate from ISE did you do it without a CSR? How did you then import it into FMC?&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2024 14:49:26 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2024-08-19T14:49:26Z</dc:date>
    <item>
      <title>Error to validate a pxGrid certificate in FMC</title>
      <link>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162671#M1115188</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I create a pxGrid certificate in ISE following this URL (&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-32/220856-configure-and-troubleshoot-ise-3-2-with.html#toc-hId--1225537032" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-32/220856-configure-and-troubleshoot-ise-3-2-with.html#toc-hId--1225537032&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;When I tried to add the internal cert in FMC I got this error:&lt;/P&gt;
&lt;P&gt;"Failed to validate Cert Based EO: System&amp;nbsp;&lt;SPAN&gt;(/usr/bin/sudo /usr/bin/openssl rsa -outform pem -inform pem -in /tmp/Sp3Kkt49CV -passin file:/tmp/5ZbeyQmSDf -out /tmp/XKD_szJlF6) Failed"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyone has an idea?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 14:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162671#M1115188</guid>
      <dc:creator>LuigiDiFronzo9542</dc:creator>
      <dc:date>2024-08-19T14:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Error to validate a pxGrid certificate in FMC</title>
      <link>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162682#M1115189</link>
      <description>&lt;P&gt;When you generated the certificate from ISE did you do it without a CSR? How did you then import it into FMC?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 14:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162682#M1115189</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-19T14:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Error to validate a pxGrid certificate in FMC</title>
      <link>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162693#M1115190</link>
      <description>&lt;P&gt;Thank you for your response Marvin,&lt;/P&gt;
&lt;P&gt;Yes I generate the certificate from ISE without a CSR like the info in the link. The certificate was downloaded in my pc and from the FMC I was able to import the cert and the private key.&lt;/P&gt;
&lt;P&gt;I generate again the pxgrid certificates in ISE and this time the FMC was able to recognize and accept the cert.&lt;/P&gt;
&lt;P&gt;I added the trusted root CA too and when I configured the integration with ISE in FMC the test failed with this error:&lt;/P&gt;
&lt;P&gt;Primary host:&lt;BR /&gt;[INFO]: PXGrid v2 is enabled&lt;BR /&gt;[ERROR]: HttpsStringRequest on_handshake error: 337047686: certificate verify failed&lt;BR /&gt;[ERROR]: HttpsStringRequest SSL error: 2024-08-19 14:48:12(GMT): Starting SSL Handshake, SSL state:before SSL initialization&lt;BR /&gt;2024-08-19 14:48:12(GMT): SSL State:before SSL initialization&lt;BR /&gt;2024-08-19 14:48:12(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:12(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:12(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:SSLv3/TLS read server hello&lt;BR /&gt;2024-08-19 14:48:13(GMT): Entering OpenSSL verify callback, preverified:0, error: self signed certificate in certificate chain, error depth: 3, current_cert: Certificate with Serial Number '0x0AF966010CFE4D8E9C19D737749986B6', issued by 'CN = Certificate Services Root CA - ISE-NR-1', to 'CN = Certificate Services Root CA - ISE-NR-1'&lt;BR /&gt;2024-08-19 14:48:13(GMT): Rejecting this certificate presented by foreign server: Certificate with Serial Number '0x6B294AD7C32F40DABB04B35A36B40977', issued by 'CN = Certificate Services Endpoint Sub CA - ISE-NR-1', to 'OU = ISE Messaging Service, CN = ISE-NR-1.domain.com'&lt;BR /&gt;...because SSL negotiation encountered error: self signed certificate in certificate chain&lt;BR /&gt;...while validating this entry in the certificate chain: Certificate with Serial Number '0x0AF966010CFE4D8E9C19D737749986B6', issued by 'CN = Certificate Services Root CA - ISE-NR-1', to 'CN = Certificate Services Root CA - ISE-NR-1'&lt;BR /&gt;2024-08-19 14:48:13(GMT): Sending SSL alert:unknown CA&lt;BR /&gt;2024-08-19 14:48:13(GMT): SSL State:error&lt;BR /&gt;[ERROR]: Performing request failed with a timeout.&lt;BR /&gt;[ERROR]: Failed to contact pxGrid node at 'w.x.y.z': Request failed with a timeout.&lt;/P&gt;
&lt;P&gt;I have to say that testing ping betwen ISE and FMC is sucesfully and the time configuration is good.&lt;/P&gt;
&lt;P&gt;It seems to be a problem with the certificate. What coud be the error and timeout issue?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162693#M1115190</guid>
      <dc:creator>LuigiDiFronzo9542</dc:creator>
      <dc:date>2024-08-19T15:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error to validate a pxGrid certificate in FMC</title>
      <link>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162713#M1115191</link>
      <description>&lt;P&gt;Your network connectivity is good.&lt;/P&gt;
&lt;P&gt;Make sure that the certificate you add and select for the MnT server and pxGrid server is the "&lt;SPAN&gt;Certificate Services Root CA - ISE-NR-1&lt;/SPAN&gt;".&lt;/P&gt;
&lt;P&gt;FMC needs to trust that and, once it does, the SSL/TLS handshake should succeed.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:39:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162713#M1115191</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-19T15:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Error to validate a pxGrid certificate in FMC</title>
      <link>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162722#M1115192</link>
      <description>&lt;P&gt;Thank you Marvin,&lt;/P&gt;
&lt;P&gt;I took the correct root certificate and now when doing the test I advanced a little more. Now this message appears:&lt;/P&gt;
&lt;P&gt;Primary host:&lt;BR /&gt;[INFO]: PXGrid v2 is enabled&lt;BR /&gt;[INFO]: pxgrid 2.0: account activate succeeded&lt;BR /&gt;[ERROR]: HttpsStringRequest on_handshake error: 337047686: certificate verify failed&lt;BR /&gt;[ERROR]: HttpsStringRequest SSL error: 2024-08-19 16:00:19(GMT): Starting SSL Handshake, SSL state:before SSL initialization&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:before SSL initialization&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:SSLv3/TLS read server hello&lt;BR /&gt;2024-08-19 16:00:19(GMT): Entering OpenSSL verify callback, preverified:0, error: self signed certificate in certificate chain, error depth: 3, current_cert: Certificate with Serial Number '0x3CE95BCC2309400F9459CEA361858338', issued by 'CN = Certificate Services Root CA - ISE-NR-1', to 'CN = Certificate Services Root CA - ISE-NR-1'&lt;BR /&gt;2024-08-19 16:00:19(GMT): Rejecting this certificate presented by foreign server: Certificate with Serial Number '0x07D9534357EE420CBADFE71C8F7A22F3', issued by 'CN = Certificate Services Endpoint Sub CA - ISE-NR-2', to 'OU = Certificate Services System Certificate, CN = ISE-NR-2.cardoniv.com'&lt;BR /&gt;...because SSL negotiation encountered error: self signed certificate in certificate chain&lt;BR /&gt;...while validating this entry in the certificate chain: Certificate with Serial Number '0x3CE95BCC2309400F9459CEA361858338', issued by 'CN = Certificate Services Root CA - ISE-NR-1', to 'CN = Certificate Services Root CA - ISE-NR-1'&lt;BR /&gt;2024-08-19 16:00:19(GMT): Sending SSL alert:unknown CA&lt;BR /&gt;2024-08-19 16:00:19(GMT): SSL State:error&lt;BR /&gt;[ERROR]: Performing request failed with a timeout.&lt;BR /&gt;[ERROR]: connection to ISE-NR-2.domain.com:8910 fails: Request failed with a timeout.&lt;BR /&gt;[INFO]: Successful connection to ISE-NR-1.domain.com:8910&lt;BR /&gt;[INFO]: These ISE Services are up: SessionDirectory, SXP, EndpointProfile, SecurityGroups, AdaptiveNetworkControl&lt;BR /&gt;[INFO]: All requested ISE Services are online.&lt;/P&gt;
&lt;P&gt;Secondary host:&lt;BR /&gt;[INFO]: PXGrid v2 is enabled&lt;BR /&gt;[ERROR]: HttpsStringRequest on_handshake error: 337047686: certificate verify failed&lt;BR /&gt;[ERROR]: HttpsStringRequest SSL error: 2024-08-19 16:00:32(GMT): Starting SSL Handshake, SSL state:before SSL initialization&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:before SSL initialization&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS write client hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:SSLv3/TLS read server hello&lt;BR /&gt;2024-08-19 16:00:32(GMT): Entering OpenSSL verify callback, preverified:0, error: self signed certificate in certificate chain, error depth: 3, current_cert: Certificate with Serial Number '0x3CE95BCC2309400F9459CEA361858338', issued by 'CN = Certificate Services Root CA - ISE-NR-1', to 'CN = Certificate Services Root CA - ISE-NR-1'&lt;BR /&gt;2024-08-19 16:00:32(GMT): Rejecting this certificate presented by foreign server: Certificate with Serial Number '0x07D9534357EE420CBADFE71C8F7A22F3', issued by 'CN = Certificate Services Endpoint Sub CA - ISE-NR-2', to 'OU = Certificate Services System Certificate, CN = ISE-NR-2.cardoniv.com'&lt;BR /&gt;...because SSL negotiation encountered error: self signed certificate in certificate chain&lt;BR /&gt;...while validating this entry in the certificate chain: Certificate with Serial Number '0x3CE95BCC2309400F9459CEA361858338', issued by 'CN = Certificate Services Root CA - ISE-NR-1', to 'CN = Certificate Services Root CA - ISE-NR-1'&lt;BR /&gt;2024-08-19 16:00:32(GMT): Sending SSL alert:unknown CA&lt;BR /&gt;2024-08-19 16:00:32(GMT): SSL State:error&lt;BR /&gt;[ERROR]: Performing request failed with a timeout.&lt;BR /&gt;[ERROR]: Failed to contact pxGrid node at 'w.x.y.z': Request failed with a timeout.&lt;/P&gt;
&lt;P&gt;What could be happen?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 16:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-to-validate-a-pxgrid-certificate-in-fmc/m-p/5162722#M1115192</guid>
      <dc:creator>LuigiDiFronzo9542</dc:creator>
      <dc:date>2024-08-19T16:08:47Z</dc:date>
    </item>
  </channel>
</rss>

