05-03-2023 01:03 AM
I have tried to connect Azure and ISE(Version 3.1 patch 6) using ROPC, but I got the following Error:
Connection to ID Store failed with error: javax.net.ssl.SSLHandshakeException: No trusted certificate found and status: 400 BAD_REQUEST
I have checked the Certificate, following Certificate are already installed and using for cisco services:
DigiCert Global Root CA
DigiCert Global Root G2 CA
Microsoft Azure TLS Issuing CA 01
Microsoft Azure TLS Issuing CA 02
Microsoft Azure TLS Issuing CA 05
Microsoft Azure TLS Issuing CA 06
do I forget any Cert or config?
I am following this documentation:
Configure ISE 3.0 REST ID with Azure Active Directory - Cisco
Best Regards
Robin
Solved! Go to Solution.
05-03-2023 07:06 AM
05-09-2023 03:41 PM
You don't need a certificate signed by a public CA, but I'm not sure if Azure will accept a self-signed certificate. I have ROPC working in my lab with ISE using an Admin certificate signed by my internal ADCS.
The error you've posted references 'NotAfter: Fri Aug 05 2022' which would seem to indicate an expired certificate is being used. I would suggest checking for any expired certificates in the System and Trusted stores.
These are the Microsoft related certificates (Trusted Certificates) I have installed in my lab that is working with ROPC.
05-03-2023 04:01 AM
05-03-2023 04:06 AM
Hi Mohammed,
thanks for you answer, the Baltimore CyberTrust Root CA was also installed in the ISE as Cisco Services...
05-03-2023 04:32 AM
05-03-2023 04:42 AM
you mean:
chose: Trust for certificate based admin authentication ?
05-03-2023 05:08 AM
this is the new ISE, just installed. so I am using the default self Cert...
05-03-2023 05:22 AM - edited 05-03-2023 05:42 AM
Yes, I meant this one 'admin authentication'. also, you need to use CA signed certificate to communicate with Azure. otherwise, it won't trust your ISE.
05-03-2023 05:43 AM
Here is the list of certs which I used.
05-03-2023 06:04 AM
for me the same, that is why I dön't unterstand...
05-03-2023 06:28 AM
05-03-2023 06:33 AM
you mean, that I need a public certifcate for admin Portal? from DigiCert Global Roort G2 CA?
05-03-2023 06:35 AM
or can I upload my self signed Cert to Azure, let Azure trust my Cert?
05-03-2023 07:06 AM
05-09-2023 01:58 AM
you mean, that I need a public cert?
I have tried using one private cert, I got this error:
05-09-2023 03:41 PM
You don't need a certificate signed by a public CA, but I'm not sure if Azure will accept a self-signed certificate. I have ROPC working in my lab with ISE using an Admin certificate signed by my internal ADCS.
The error you've posted references 'NotAfter: Fri Aug 05 2022' which would seem to indicate an expired certificate is being used. I would suggest checking for any expired certificates in the System and Trusted stores.
These are the Microsoft related certificates (Trusted Certificates) I have installed in my lab that is working with ROPC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide