<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: aaa rules certificate address mismatch problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427166#M708278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we solved it by using identity&lt;/P&gt;&lt;P&gt;certificate on ASA that has all server names that are accessed, stated in CN of certificate, a&lt;/P&gt;&lt;P&gt;nd this is working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Jul 2010 17:44:16 GMT</pubDate>
    <dc:creator>draganskundric</dc:creator>
    <dc:date>2010-07-01T17:44:16Z</dc:date>
    <item>
      <title>aaa rules certificate address mismatch problem</title>
      <link>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427164#M708255</link>
      <description>&lt;P&gt;I have several web sites with different names that are protected by aaa rules and external radius server against which user must authenticate. Problem is that when fw send its page with username and password, browser reports certificate address mismatch, because ther is difference between site name in ASA self signet certificate and site that is accessed. Is there a way to avoid this by some config in ASA. I know it is possible to turn off this check in IE, but thi is not preffered way for solving this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427164#M708255</guid>
      <dc:creator>draganskundric</dc:creator>
      <dc:date>2019-03-11T18:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: aaa rules certificate address mismatch problem</title>
      <link>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427165#M708267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dragan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've played long time ago and only in the lab with CTP so I was never bothered by warnings.&lt;/P&gt;&lt;P&gt;What do you have configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try using redirect with listener?&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1556188"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1556188&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Do you have secure client enabled?&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1556729"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1556729&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm not sure if even installing a proper cert on the ASA/PIX will help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jun 2010 17:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427165#M708267</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-06-29T17:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: aaa rules certificate address mismatch problem</title>
      <link>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427166#M708278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we solved it by using identity&lt;/P&gt;&lt;P&gt;certificate on ASA that has all server names that are accessed, stated in CN of certificate, a&lt;/P&gt;&lt;P&gt;nd this is working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 17:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-rules-certificate-address-mismatch-problem/m-p/1427166#M708278</guid>
      <dc:creator>draganskundric</dc:creator>
      <dc:date>2010-07-01T17:44:16Z</dc:date>
    </item>
  </channel>
</rss>

