cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4257
Views
1
Helpful
5
Replies

ISE + SCEP + Internal CA + iPads

RichardAtkin
Level 3
Level 3

Morning,

 

I'm trying to use ISE's internal CA with SCEP to issue unique Certificates to some iPads so we can do EAP-TLS on the Wireless.

 

We're pushing the SCEP config to the client via a separate MDM platform, we can see the client hitting the SCEP URL on ISE (via TCPDump), but it never gets a Cert and there's very little (ie, nothing!) in the logs to help troubleshoot.  Logging in the ISE seems minimal (any clues on what logs to look at?) and the ISE config guides for this kind of thing are all old and reference external CAs only.

 

When I put the SCEP URL the client is trying to access in my browser, it returns this;

 

SCEP URL: http://ISE-FQDN:9090/auth/caservice/pkiclient.exe?operation=GetCACert&message=ISE-Hostname

Error:  "Block scep enrollment as the traffic does not come from network device

 

Any tips please?!

 

Cheers,

Richard

5 Replies 5

sj3fk3
Level 1
Level 1

Hello Richard, I know it's some time ago but I had the same issue.

 

You get the "Block scep enrollment as the traffic does not come from network device" if the device ip is not known in the network devices list.

 

Just add the ip of the device or MDM in Administration -> Network Resources -> Network devices.

 

 

Hi

 

I was wondering if you ever got this working without the MDM... I am trying to simply do a SCEP enrolment into ISE with the internal CA (my lab runs all personas) but am having issues wondering what a potential enrollment password could be. I know no way of configuring these settings within ISE.

 

Can you please assist with some guidance on where I could start looking? Recommend any good resources to consult.

 

Thanks,

Chris 

Hi,

If you are using windows as internal CA, you need to disable "password
challenge" to get fully automated enrollment. I wrote two parts blog on how
to do this with ASA (similar process can followed for ISE).

Here are the blogs

https://tek-board.blogspot.com/2015/01/cisco-asa-scep-proxy-enrollment-part-1.html
https://tek-board.blogspot.com/2015/01/cisco-asa-scep-proxy-enrollment-part-2.html

Here are the steps to disable password challenge.


1. On CA server, open the Group Policy Management console.
2. In the console tree, double-click Group Policy Objects in the forest
and domain containing the Default Domain Policy Group Policy object
(GPO) that you want to edit.
3. Right-click the Default Domain Policy GPO, and then click Edit.
4. In the Group Policy Management Console (GPMC), click User
Configuration, Policies, Windows Settings, Security Settings, and then
click Public Key Policies.
5. Double-click Certificate Services Client - Auto-Enrollment.
6. In Configuration Model, select Enabled to enable autoenrollment. If
you want to disable autoenrollment, select Disabled.
7. If you are enabling certificate autoenrollment, you can select the
following check boxes:
- Renew expired certificates, update pending certificates, and remove
revoked certificates
- Update certificates that use certificate templates
- Expiration notification
8. Click OK to accept your changes.


To verify that password challenge is disabled:

1. Click Start and enter regedit in the search bar.
2. Navigate to Computer > HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft >
Cryptography > MSCEP > EnforcePassword.
3. Ensure that the EnforcePassword value is set to 0 (the default value
is 1).

Thanks Mohammed,

 

But I am using the internal ISE CA and not an external MS.

I have this post opened to explain my situation... 

https://community.cisco.com/t5/network-access-control/endpoint-on-boarding-using-internal-ise-ca/m-p/4456367#M569326

 

My endpoints are not MS clients but Dell ThinOS - and I don't have an MDM but the Wyse Management Suite  (WMS). I'm trying to request a certificate from ISE PSN but unsure its properly configured to permit it... As I don't see any RA type certificate in my trusted store on ISE.

 

I do have the ip address of my endpoint defined in the network devices page - but unsure how I will be able to deploy long term with this requirement as I am trying to setup some automation with SCEP to hundreds of Dell endpoints.

 

Thanks,

Chris 

chris-lawrence
Level 1
Level 1

Hi Richard,

 

You posted this awhile ago...

 

I'm trying somewhat do the same using Dell Wyse Thin Client endpoints... but no MDM involved. I added its IP to the network devices and it did allow me further but I don't know how the set the variables the "Registration Authority" needs to properly enrol into the ISE Internal-CA. Did you get something working?

 

Thanks,

Chris