Hi all,
I am running an ISE 2.1 and playing around with BYOD right now. The solution for Android with the App download is IMHO pure garbage. Can't just allow full internet access and downloading an App is also not ideal.
So I am running it witout provisioning. Found the same configuration here: https://supportforums.cisco.com/blog/12705471/ise-byod-registration-only-without-native-supplicant-or-certificate-provisioning
The problem now is that I can't check if our root CA is installed on the client.
Without using the certificate the connections are vulnerable of identity theft. Is there a way to get the root ca certrificate that signed the eap cert of ISE to the clients? Or is it possible to check from ise if the root certificate is installed on the clients and used for the server identity check?
Regards
Saius