<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CA problem with NAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395505#M825243</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Victor,&lt;/P&gt;&lt;P&gt;What error are you getting during the certificate import? You need to create a&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A class="active_subtablink" href="https://172.30.3.66/admin/x509_req.faces?CCA_TOKEN=cQlzwStCcYviYnXuyz-TrL-OpMyuE15zfA025sRjvnU."&gt;X509 Certification Request&lt;/A&gt;&amp;nbsp; (for CAS and also for CAM) under the SSL certificate section. Export the request (remember to select the Private Key also during the export of the request).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then follow the steps in the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://technet.microsoft.com/en-us/library/cc736590%28WS.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/cc736590%28WS.10%29.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After getting the certificate follow steps to import the certificate outlined in the NAC configuration Guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Stanslaus.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Feb 2010 12:53:10 GMT</pubDate>
    <dc:creator>IT_Data_CorporateNet</dc:creator>
    <dc:date>2010-02-26T12:53:10Z</dc:date>
    <item>
      <title>CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395497#M825228</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;I'm using Internal CA (Microsoft Win 2003 CA) to provide SSL certificates to NAC. The problem is that, end users are still getting warnings on login to the network the same way as when i was using the Perfigo Certificate. I've tried to install the server certificate to clients but still the CA is seems to be untrusted. Does this mean that i have to buy certificates from trusted Authorities like Verisign or still there is something i can do to my CA? Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Stanslaus.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395497#M825228</guid>
      <dc:creator>IT_Data_CorporateNet</dc:creator>
      <dc:date>2020-02-21T11:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395498#M825230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stanslaus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to take the Root certificate and install that on the clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Dec 2009 18:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395498#M825230</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-12-15T18:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395499#M825231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;Thanks for your reply. See the attachment. When on clients i click on "&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial;"&gt;To trust certificates issued from this certification authority, &lt;A href="http://tzvodafs02/certsrv/certnew.cer?ReqID=CACert&amp;amp;Renewal=0&amp;amp;Mode=inst&amp;amp;Enc=b64" onmouseout="" onmouseover=""&gt;install this CA certificate&lt;/A&gt;.'&lt;/SPAN&gt;". I'm not very good on setup PKI. How do i get and install the root certificate. My CA is Standalone Root CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Stanslaus.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Dec 2009 18:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395499#M825231</guid>
      <dc:creator>IT_Data_CorporateNet</dc:creator>
      <dc:date>2009-12-15T18:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395500#M825232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stanslaus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you click on that link, does it tell you to download a cert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, take that file to the client and double click on it. It should install in the correct store automatically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Dec 2009 18:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395500#M825232</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-12-15T18:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395501#M825233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;Happy new year 2010!!.&lt;/P&gt;&lt;P&gt;I was on leave and had no time to work on this.&lt;/P&gt;&lt;P&gt;Thanks for your assistance. I had two warnings one was that "The Certificate was not from a trusted authority" (Resolved by you last reply) and the other is saying that "The Certificate does not match the site you are viewing". This is still persisting. Please if you know the reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Stanslaus.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2010 08:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395501#M825233</guid>
      <dc:creator>IT_Data_CorporateNet</dc:creator>
      <dc:date>2010-01-19T08:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395502#M825234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stanslaus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second problem will come up if you're trying to access the device in question with a name that is different than what the cert says the name should be. For example if your cas is named cas1.abc.com and you try to access it with the url consisting of the ip address for that CAS, you will see that message. Ensure that the CN you have for the certificate is what you're using to access the CAS and you shouldn't see that problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jan 2010 04:22:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395502#M825234</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-01-24T04:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395503#M825235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Faisal,&lt;/P&gt;&lt;P&gt;At the begining i created Certificate requests using FQDN of the appliances as CN. Although i could access the appliances using FQDNs for some reasons CAS was redirecting using IP Address. I've recreated the Certificates using IPs as CNs and now it is working fine. Thank you very much for your support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Stanslaus.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jan 2010 17:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395503#M825235</guid>
      <dc:creator>IT_Data_CorporateNet</dc:creator>
      <dc:date>2010-01-24T17:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395504#M825238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello. Could you help on how you managed to get the Microsoft CA to issue&lt;/P&gt;&lt;P&gt;certificates for NAC. I'm having trouble installing them in NAC and am not sure that I am requesting them correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Victor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Feb 2010 16:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395504#M825238</guid>
      <dc:creator>rhobab</dc:creator>
      <dc:date>2010-02-22T16:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395505#M825243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Victor,&lt;/P&gt;&lt;P&gt;What error are you getting during the certificate import? You need to create a&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A class="active_subtablink" href="https://172.30.3.66/admin/x509_req.faces?CCA_TOKEN=cQlzwStCcYviYnXuyz-TrL-OpMyuE15zfA025sRjvnU."&gt;X509 Certification Request&lt;/A&gt;&amp;nbsp; (for CAS and also for CAM) under the SSL certificate section. Export the request (remember to select the Private Key also during the export of the request).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then follow the steps in the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://technet.microsoft.com/en-us/library/cc736590%28WS.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/cc736590%28WS.10%29.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After getting the certificate follow steps to import the certificate outlined in the NAC configuration Guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Stanslaus.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 12:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395505#M825243</guid>
      <dc:creator>IT_Data_CorporateNet</dc:creator>
      <dc:date>2010-02-26T12:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: CA problem with NAC</title>
      <link>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395506#M825248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have managed to solved the problem. I had to convert the certificates supplied by the Microsoft CA from DER to PEM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Victor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 14:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ca-problem-with-nac/m-p/1395506#M825248</guid>
      <dc:creator>rhobab</dc:creator>
      <dc:date>2010-02-26T14:35:01Z</dc:date>
    </item>
  </channel>
</rss>

