<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL problems with VeriSign certificates in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971279#M68714</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is that Verisign gave you a chained cert.  They will stop issuing root unchained certs in the end of September.  So your best bet is to go with RapidSSL or if you really want a Verisign cert, is to call them and request one.  They will tell you that they will no longer support it in the future.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WLC doesn't support any chained certs only root CA unchained certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Jul 2008 10:26:38 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2008-07-01T10:26:38Z</dc:date>
    <item>
      <title>SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971278#M68713</link>
      <description>&lt;P&gt;I'm running an WLAN with a pair of ACS3.3(2) servers and 1200 series APs. I use AES encryption and Peap MS-chap authentication.&lt;/P&gt;&lt;P&gt;Everything was running fine until I renewed the SSL cert for the two servers. After the new cert was installed a large number of clients could not connect. A workaround was to check the option "Allow intermediate certificates" on the client. Some clients don't even have this option and I didn't want to have to reconfigure all the clients (in the 1000s) unless absolutely necessary as most don't have SMS yet. I ended up installing a certificate without an intermediate CA from RapidSSL and it works as before. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a TAC case open but this only came to the conclusion that the new certificate was the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else got this working or is this unsupported?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 23:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971278#M68713</guid>
      <dc:creator>patrickdonlon</dc:creator>
      <dc:date>2021-07-03T23:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971279#M68714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is that Verisign gave you a chained cert.  They will stop issuing root unchained certs in the end of September.  So your best bet is to go with RapidSSL or if you really want a Verisign cert, is to call them and request one.  They will tell you that they will no longer support it in the future.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WLC doesn't support any chained certs only root CA unchained certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jul 2008 10:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971279#M68714</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2008-07-01T10:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971280#M68715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got in touch with Verisign and have now been issued with unchained certs. They also said end of Sept is when they stop doing this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if Cisco is working on integrating this into the WLC? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 07:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971280#M68715</guid>
      <dc:creator>patrickdonlon</dc:creator>
      <dc:date>2008-07-07T07:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971281#M68716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only thing with this is that the wlc has to be able to look up and verify the chained cert.  So far, I haven't heard that they will support this since you can get unchained root certs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 10:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971281#M68716</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2008-07-07T10:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971282#M68717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have solved one problem and it seems created even more. The XP clients in more than one country can't authenticate unless they uncheck the validate certificate option. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean the cert is not correctly installed on the ACS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been sent screen shots of the client config and they would accept a cert when it was configured. Is this normal or is again a server issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jul 2008 18:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971282#M68717</guid>
      <dc:creator>patrickdonlon</dc:creator>
      <dc:date>2008-07-08T18:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971283#M68718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No... check the client side, they might have to check one of the the Trusted Root Certification Authorities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jul 2008 19:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971283#M68718</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2008-07-08T19:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSL problems with VeriSign certificates</title>
      <link>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971284#M68719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just thought I'd follow up on this one, it turned out the Rapid SSL wasn't trusted on the clients, probably as it was a month trial. The Verisign unchained cert fixed the last of the problems,&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2008 13:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-problems-with-verisign-certificates/m-p/971284#M68719</guid>
      <dc:creator>patrickdonlon</dc:creator>
      <dc:date>2008-07-15T13:49:51Z</dc:date>
    </item>
  </channel>
</rss>

