10-25-2017 12:55 PM
Hello all. I am attempting to add ISE 2.3 into our test environment and use it as the internal CA. We currently are using a Windows CA successfully but would like to transition away from it. We are using devices that can not go through the onboarding process and must use the Certificate Provisioning Portal and CSRs. When we attempt to create certificates from the CSR we are receiving an general error "CA Server Error" with no other explanation. I have looked into the logs, and see the request and then errors like "getNADAddress: radiusSessionId is not found. Probably a test URL." and "interface bond0 is selected, but eth0 and eth1 are not bonded together as interface bond0, so the portal cannot listen on this interface. Since eth0 and/or eth1 are also selected for this portal, the physical interface(s) will be used instead. " The only thing that I see related directly to the request is "san=<User Name>, cn=, description=, certOperation=SINGLE_CERT_REQ_WITH_CSR, templateName=EAP_Authentication_Certificate_Template, downloadFormat=PKCS8" where the CN is blank, though looking at the CSR with OpenSSL we see the CN listed.
Any pointers to find what the "CA Server Error" is or how to guides for the Certificate Provisioning would be appreciated.
Solved! Go to Solution.
10-25-2017 07:16 PM
If it working without CSR, then some fields on your CSR might not be compatible.
I would suggest to engage Cisco TAC. Or, provide us a copy of a sample CSR that giving you such errors.
10-25-2017 07:16 PM
If it working without CSR, then some fields on your CSR might not be compatible.
I would suggest to engage Cisco TAC. Or, provide us a copy of a sample CSR that giving you such errors.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide