<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Renewal Certificate ISE in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913813#M17572</link>
    <description>Dear Ammahend&lt;BR /&gt;Root cert already verified by Zone.&lt;BR /&gt;So in the ISE end, i need to enable: Trust for client authentication and Syslog ?&lt;BR /&gt;Thanks&lt;BR /&gt;DungTran</description>
    <pubDate>Mon, 26 Aug 2019 04:36:15 GMT</pubDate>
    <dc:creator>dungtran.90</dc:creator>
    <dc:date>2019-08-26T04:36:15Z</dc:date>
    <item>
      <title>Renewal Certificate ISE</title>
      <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3912774#M17568</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an ISE node. EAP certificate is expired so I renewal it and received the certificate from Zone which is using normal for other sites ( Europe, India, America..) But in Vietnam, we met the issue as the picture below. We change the EAP certificate from Comodo to Sectigo. Import successfully to ISE, a client can connect now, but it does not automatically connect anymore, every time we move to another AP we need to click connect twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="One.JPG" style="width: 616px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/43628i66538B0A3DC23AE3/image-size/large?v=v2&amp;amp;px=999" role="button" title="One.JPG" alt="One.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please help or support?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;DungTran&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3912774#M17568</guid>
      <dc:creator>dungtran.90</dc:creator>
      <dc:date>2021-07-05T17:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Renewal Certificate ISE</title>
      <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913036#M17569</link>
      <description>Do you have more than one Radius server configured? If yes, do both use the same root certificate / issuer of the certificate?&lt;BR /&gt;If not, then this is the normal behavior.&lt;BR /&gt;Make sure that the certificate shown to the client is actually the correct one and not a Man in the Middle attack with a rogue access point.</description>
      <pubDate>Fri, 23 Aug 2019 12:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913036#M17569</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-08-23T12:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Renewal Certificate ISE</title>
      <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913098#M17570</link>
      <description>&lt;P&gt;"show certificate details" may guide you to the root cause&lt;/P&gt;&lt;P&gt;possibilities:&lt;/P&gt;&lt;P&gt;- the host-name does not match the name in the certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; this would be immediately shown&amp;nbsp;&lt;/P&gt;&lt;P&gt;- when using multiple ISE servers , you may need to configure SAN names in the certificate&lt;BR /&gt;&amp;nbsp; certificate details -&amp;gt; alternate names&lt;/P&gt;&lt;P&gt;- you may have imported a certificate with incorrect certification-chaining&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; certificate details -&amp;gt; certification path&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 14:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913098#M17570</guid>
      <dc:creator>pieterh</dc:creator>
      <dc:date>2019-08-23T14:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Renewal Certificate ISE</title>
      <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913582#M17571</link>
      <description>&lt;P&gt;Some additional basic checks ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;verify&amp;nbsp;&lt;SPAN&gt;Sectigo root cert chain in present on client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On ISE end I am sure you check Sectigo root cert to be used for client authentication.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2019 22:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913582#M17571</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2019-08-24T22:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Renewal Certificate ISE</title>
      <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913813#M17572</link>
      <description>Dear Ammahend&lt;BR /&gt;Root cert already verified by Zone.&lt;BR /&gt;So in the ISE end, i need to enable: Trust for client authentication and Syslog ?&lt;BR /&gt;Thanks&lt;BR /&gt;DungTran</description>
      <pubDate>Mon, 26 Aug 2019 04:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913813#M17572</guid>
      <dc:creator>dungtran.90</dc:creator>
      <dc:date>2019-08-26T04:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Renewal Certificate ISE</title>
      <link>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913840#M17573</link>
      <description>&lt;P&gt;yes If you are using this certificate for client EAP auth.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 05:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/renewal-certificate-ise/m-p/3913840#M17573</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2019-08-26T05:37:51Z</dc:date>
    </item>
  </channel>
</rss>

