cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
963
Views
2
Helpful
5
Replies

CPP and Admin certificate different but on same interface

gvanbon
Cisco Employee
Cisco Employee

Hi,


Configured the following on ISE 2.3:

1 ISE interface for CPP and Admin

CCP portal runs on TCP port 8443 with its own certificate signed by CA1

Admin portal runs on port 443 with its own certificate signed by CA2

When a CCP redirection occurs, the client first get redirected on port 443 (with the wrong certificate) and to port 8443 with the right certificate.

I would have expected that the client would directly go to the 8443 port.

Anybody seen this ?

Thanks

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Yes, I've been seeing it during beta. This appears related to CSCve85686.

View solution in original post

5 Replies 5

hslai
Cisco Employee
Cisco Employee

Yes, I've been seeing it during beta. This appears related to CSCve85686.

I have the same in ISE 2.2 - I raised a TAC case for it.  They told me it was due to CSCut16630 (ancient bug).

Luckily I have an F5 load balancer that is masking this issue. 

We have an enhancement bug -- CSCva84197, but we have not scheduled to address it yet.

gvanbon
Cisco Employee
Cisco Employee

Thanks all !

The ISE installation guide 2.3 states that ISE presents Admin cert for Posture and CPP, then Portal cert for 8443. So I doubt if it’s really a bug. All the installation guides from 1.2 to 2.3 state this.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: