<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Supplicant Based Extended Node onboarding certificate issue in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5167466#M3492</link>
    <description>&lt;P&gt;That's what we feared. Thank you! I tested in lab and it works well. Now we just have to wait for an appropriate time to change certificate.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 07:51:35 GMT</pubDate>
    <dc:creator>kimhi</dc:creator>
    <dc:date>2024-08-29T07:51:35Z</dc:date>
    <item>
      <title>Supplicant Based Extended Node onboarding certificate issue</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5166504#M3489</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have used this guide to configure our SBEN&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-5/user_guide/b_cisco_dna_center_ug_2_3_5/b_cisco_dna_center_ug_2_3_5_chapter_01110.html#Cisco_Concept.dita_5214333f-f583-4fd1-a3db-093ca3f6e8cd" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-5/user_guide/b_cisco_dna_center_ug_2_3_5/b_cisco_dna_center_ug_2_3_5_chapter_01110.html#Cisco_Concept.dita_5214333f-f583-4fd1-a3db-093ca3f6e8cd&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue we're facing is that DNAC is pushing the wrong root certificate for ISE, so the switch, in our case a C9200CX, rejects the ISE certificate during dot1x authentication and ends up in an unreachable state due to our default deny setup. I've managed to put the correct certificate onto the switch manually before authorizing it and it all works perfectly when I do, but that defeats the point of automatic onboarding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it a requirement for the root certificates of DNAC and ISE to be the same for this to work or is DNAC supposed to push down the trustpoool bundle where the correct root certificate is?&lt;/P&gt;&lt;P&gt;I have also tried to put the certificate on the switch using a day0 template, but had no luck due to the limitations of day0 templates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5166504#M3489</guid>
      <dc:creator>kimhi</dc:creator>
      <dc:date>2024-08-27T12:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Supplicant Based Extended Node onboarding certificate issue</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5166563#M3490</link>
      <description>&lt;P&gt;check for this Trustpoint &amp;lt;custom-dnac-ca-name&amp;gt;:&lt;BR /&gt;Issuing CA certificate configured:&lt;BR /&gt;Subject Name:&lt;BR /&gt;cn=My company Root CA,ou=My company Services,o=My company Group&lt;BR /&gt;u need to configure it on DNAC in similar manner so that your ISE EAP certificate has the same TL issuer "My company Root CA"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 14:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5166563#M3490</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-08-27T14:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Supplicant Based Extended Node onboarding certificate issue</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5167466#M3492</link>
      <description>&lt;P&gt;That's what we feared. Thank you! I tested in lab and it works well. Now we just have to wait for an appropriate time to change certificate.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/supplicant-based-extended-node-onboarding-certificate-issue/m-p/5167466#M3492</guid>
      <dc:creator>kimhi</dc:creator>
      <dc:date>2024-08-29T07:51:35Z</dc:date>
    </item>
  </channel>
</rss>

