05-03-2024 09:34 AM
Hello,
We have installed the public CA signed cert in the ISE nodes.
this is for BYOD devices which we are not managing so whenever apple devices trying to connect Wi-Fi using 802.1X auth they still need to manually trust the certificate for connection. we don't have the same problem with Android/Windows devices.
Let me know if you guys have any suggestions.
Regards,
Kunal Shah
05-03-2024 09:41 AM
M.
05-03-2024 10:28 AM
@kshah2589 iDevices (iPad's/iPhones) have to manually Trust the certificates for each PSN.
Refer to the Cisco Live presentation BRKSEC-2234
You can resolve this by using a WildSAN or MultiSAN certificate, the same certificate is used by all PSNs for the EAP authentication.
05-03-2024 11:19 AM
We are using MultiSAN certificate with same certificate installed in both PSN but still getting an error.
05-03-2024 10:34 AM
Sorry can you more elaborate
How many PSN you have
What is CN and SAN you use in your PSN identity Cert
Thanks
MHM
05-03-2024 11:21 AM
We have 2 PSN in our environment one in east coast and second in west coast , CN = abc.domain.com and SAN1 = abc.domain.com(first PSN) and SAN2 = xyz.domain.com(second PSN)
05-03-2024 12:32 PM
OK, can you try this
add new test WLAN and add first PSN only as AAA server and check if the macOS can connect or not.
if it can connect then issue with SAN of Cert
MHM
05-03-2024 01:16 PM
Thanks for suggestions but Android/Windows doesn't have problem. Do you still want to me test?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide