cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

629
Views
5
Helpful
2
Replies
Highlighted
Beginner

ISE trusted certificates - 1.1.1 bug??

Hello,

I'm authenticating a few Cisco Phones towards ISE via EAP-TLS, and all was working on version  version 1.1.

Now that we've upgraded to 1.1.1, I've reimported Cisco's Manufacturing CA and Root CA certificates into ISE, and marked them for trust for EAP-TLS authentications, but when phones authenticate I keep getting the message that they've presented an unknown CA certificate in their certificate request, and obviously we are failing EAP-TLS, but I'm pretty sure the certificates are well imported into ISE, so they should pass the validation.

Is anybody aware of a bug of some sort with this?

I read a post where somebody stated that now ISE would only support one certificate for EAP-TLS auth...

If somebody can provide further details...

Thanks

Gustavo Novais

Everyone's tags (5)
2 REPLIES 2
Highlighted
Enthusiast

ISE trusted certificates - 1.1.1 bug??

Hello,

The bug has been resolved in the new update of ISE 1.1.2 and the higher versions.

Ref. Link:   http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html

Highlighted
Cisco Employee

ISE trusted certificates - 1.1.1 bug??

The defect that I come across even I had all the certs installed correctly.

CSCud00831    eap-tls authentications start failing after a while x509 decrypt error

Symptom:

EAP-TLS authentications fail with "X509 decrypt error"

Conditions:

Visiting backup/restore page or performing an automatic scheduled backup

without visiting the backup/restore page

Workaround:

Do not visit backup page. Disable scheduled backup. Separate Policy

Services. Node on deployment from Administrative or Monitoring Node.

The fix will be available in ISE 1.1.3

Jatin Katyal


- Do rate helpful posts -

~Jatin Katyal