<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate Question. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122457#M218114</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a 5500 controller with one of the WLANS using 802.1X authentication.&lt;/P&gt;&lt;P&gt;We are going to revoke the certificate (retiring the CA) and want to use a different cert.&lt;/P&gt;&lt;P&gt;Do I specify the cert in the Controller Admin page or only in the Network Policy properties on the NPS server (2008r2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or am I just talking gibberish?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drew&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 06:21:18 GMT</pubDate>
    <dc:creator>Andrew Cormier</dc:creator>
    <dc:date>2021-07-04T06:21:18Z</dc:date>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122457#M218114</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a 5500 controller with one of the WLANS using 802.1X authentication.&lt;/P&gt;&lt;P&gt;We are going to revoke the certificate (retiring the CA) and want to use a different cert.&lt;/P&gt;&lt;P&gt;Do I specify the cert in the Controller Admin page or only in the Network Policy properties on the NPS server (2008r2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or am I just talking gibberish?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drew&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122457#M218114</guid>
      <dc:creator>Andrew Cormier</dc:creator>
      <dc:date>2021-07-04T06:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122458#M218115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The certificate needs to be on the radius server since your doing 802.1x.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 00:53:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122458#M218115</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-16T00:53:58Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122459#M218116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;I agree with Scott. The certificate must be on the RADIUS server (NPS in your case).&lt;/P&gt;&lt;P&gt;During the authentication phase, the client communicates with the server and validates the certificate of the server. The controller only forwards the traffic back and forth between the client and the server. The clietns need to verify the radius certificate and the issuer's root CA certificate of the server must be installed on the trusted list in the client's machine in order to consider it acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, just like Scott said, the certificate must be on the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 07:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122459#M218116</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-01-16T07:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122460#M218117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Client validation is optional for some clients. Not mandatory. I only note this because you can get yourself in trouble with this one &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 12:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122460#M218117</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-01-16T12:47:33Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122461#M218118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Love this forum. Thanks guys.&lt;/P&gt;&lt;P&gt;I will try it at lunch time and update/rate your responses &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 14:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122461#M218118</guid>
      <dc:creator>Andrew Cormier</dc:creator>
      <dc:date>2013-01-16T14:48:29Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122462#M218119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would assume that since your NPS is part of the domain, when you bring up the new CA, it would push certificates to all existing servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 15:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122462#M218119</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-16T15:30:14Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122463#M218120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yeah Scott.&lt;/P&gt;&lt;P&gt;Not a best practice but we promoted a second enterprise CA in tandem with the first. &lt;/P&gt;&lt;P&gt;We only use certs for two things.. OCS and Wireless so it isnt a big deal to revoke.&lt;/P&gt;&lt;P&gt;The second GC came up about a month ago. Anyone who hasnt gotten it as a trusted root will have issues but that should be pretty small. We already did OCS and weeded most of the problems then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think changing the cert on the Radius server will cause users to reauthenticate? If there is a problem and it doesnt work would I see it right away with existing active connections or only when a use tries to connect ? Know what I mean?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 15:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122463#M218120</guid>
      <dc:creator>Andrew Cormier</dc:creator>
      <dc:date>2013-01-16T15:35:42Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122464#M218121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are validating the server certificate, then yes that will be an issue.&amp;nbsp; You would have to trust that new server certificate, push that out in GPO and then adjust the GPO wireless profile to trust the new server certificate.&amp;nbsp; It might be easier if you are validating the server certificate is to push out a new wireless profile that doesn't validate the server certificate.&amp;nbsp; This way devices will not be affected.... Then put the new certificate on the NPS and allow devices to connect and monitor any issues.&amp;nbsp; Then you can update the wireless GPO policy to trust the new server cert.&amp;nbsp; This way, since most people never plug in, they will still be connected to the wireless and able to get a GPO push.&amp;nbsp; Makes sense? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 15:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122464#M218121</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-16T15:40:22Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122465#M218122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Validating the certificate is a double edge sword. It takes planning. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From personal experience I will leave you with this one statement: If you validate the certificate, you need to make sure you have a means to manage that change through a PUSH mechanism. There will come a day that you might need to change the name of the trusted site. If you don't have a means to push, then you will need to touch each and every device.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 16:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122465#M218122</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-01-16T16:03:33Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122466#M218123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Went into NPS... changed the cert for the new one. My existing connection stayed up.&lt;/P&gt;&lt;P&gt;Disconnected and joined another WLAN.. reconnect to the 802.1x net no issues.&lt;/P&gt;&lt;P&gt;Rebooted and automatically connected the 802.1x net&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joy &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks to all !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 17:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122466#M218123</guid>
      <dc:creator>Andrew Cormier</dc:creator>
      <dc:date>2013-01-16T17:27:04Z</dc:date>
    </item>
    <item>
      <title>Certificate Question.</title>
      <link>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122467#M218124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad you got it working! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 18:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-question/m-p/2122467#M218124</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-16T18:24:42Z</dc:date>
    </item>
  </channel>
</rss>

