05-30-2020 07:43 PM
Hi,
I have encountered error for all dot1x devices like laptop where DenyAccess. other non devices seems working fine.
ISE error below seen. Previously all was working fine till recently.
Any idea guys? Thanks!
| OpenSSLErrorMessage | SSL alert: code=0x230=560 \; source=remote \; type=fatal \; message="unknown CA" |
| OpenSSLErrorStack | 14384:error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca:s3_pkt.c:1494:SSL alert number 48 |
05-31-2020 12:14 AM
Is any certification renwed recently ?
i see bug here similar kind : (since we do not know what version of ISE you running) worth looking is this effects your environment :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf41214/?rfs=iqvred
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
05-31-2020 07:05 AM
Hi,
Some locations are working fine though. But the cert did not expired. Previously they were working fine and then suddenly all wasn't working. Could this be laptop's certificate issues? How can I compare the certs in ISE with the certs in laptop?
What attributes needs to match the which certs in ISE for wired-dot1x devices to authenticated successfully?
05-31-2020 07:13 AM
Hi,
I am running ISE 2.4
05-31-2020 07:57 AM
06-01-2020 09:31 PM
Start with CiscoLive BRKSEC-3229 if you want to debug it yourself. Otherwise, please open a case with Cisco TAC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide