cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
890
Views
2
Helpful
7
Replies

Apple Devices not trusting public CA signed cert when connect 802.1X

kshah2589
Level 1
Level 1

Hello,

We have installed the public CA signed cert in the ISE nodes.

this is for BYOD devices which we are not managing so whenever apple devices trying to connect Wi-Fi using 802.1X auth they still need to manually trust the certificate for connection. we don't have the same problem with Android/Windows devices.

Let me know if you guys have any suggestions.

Regards,

Kunal Shah

7 Replies 7

marce1000
Hall of Fame
Hall of Fame

 

 - FYI : https://community.cisco.com/t5/network-access-control/ios-wireless-users-being-prompted-to-trust-public-certificate/m-p/3826323#M474846

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

@kshah2589 iDevices (iPad's/iPhones) have to manually Trust the certificates for each PSN.

Refer to the Cisco Live presentation BRKSEC-2234

RobIngram_1-1714756905849.png

You can resolve this by using a WildSAN or MultiSAN certificate, the same certificate is used by all PSNs for the EAP authentication.

RobIngram_0-1714756723763.png

RobIngram_2-1714757250299.png

 

 

We are using MultiSAN certificate with same certificate installed in both PSN but still getting an error.

Sorry can you more elaborate 

How many PSN you have 

What is CN and SAN you use in your PSN identity  Cert 

Thanks 

MHM

We have 2 PSN in our environment one in east coast and second in west coast , CN = abc.domain.com and SAN1 = abc.domain.com(first PSN) and SAN2 = xyz.domain.com(second PSN)

OK, can you try this
add new test WLAN and add first PSN only as AAA server and check if the macOS can connect or not.
if it can connect then issue with SAN of Cert 

MHM

Thanks for suggestions but Android/Windows doesn't have problem. Do you still want to me test?