03-20-2019 10:03 AM - edited 03-20-2019 10:05 AM
Hi Experts,
I have a customer who is performing Posture in windows machines. When the posture starts it gives an error that the server is not trusted.
We are using a CA signed cert for all the portals. (ISE FQDN in CN)
Admin and BYOD portal-only uses Self Signed Cert. (ISE FQDN in CN)
posture.xml file we have added the ISE FQDNs in the call-home.
CA Root cert is present in the PC Trusted store.
When the posture starts the redirect-url will have the FQDN present and ISE provides the CPP cert which is CA-signed and hence we should not get this error.
Is my understanding correct?
03-20-2019 12:20 PM
Hi,
does your admin certificate have those FQDN entered in the as a SAN name for those portals?
As the intial request goes to FQDN of ISE and then re-directs from there.
03-21-2019 11:02 PM
In the ISE1 Admin Cert -- which is the Self Signed one, we have the wildcard in the SAN, and FQDN in CN
Eg :
CN : abc-01.cisco.com
SAN: DNS: *.cisco.com
03-21-2019 11:05 PM - edited 03-21-2019 11:05 PM
I also notice a behaviour that when the error comes in anyconnect, it states IP address instead of FQDN, which can cause the issue. Where is the IP address taken from? cos URL, and Posture.xml has the FQDN ?
03-22-2019 02:32 AM
Same issue has been discussed here with a workaround- https://community.cisco.com/t5/identity-services-engine-ise/anyconnect-posture-certificate-error/td-p/3580733
Thanks,
Nidhi
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide