cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2149
Views
0
Helpful
2
Replies

Cisco ISE Subject not found in the applicable identity store(s)

mrjelly
Level 1
Level 1

Hello,

I am getting an error with a printer authenticating with Cisco ISE for dot1x.

The error is "Subject not found in the applicable identity store(s)".

This is an LDAP identity lookup. It is looking for the alternative subject name DNS, and this is all being seen in the certificate, I can see this in the logs.

In the identity store, if I go to the attribute tab, I can find the printer there so ISE itself appears to be able to see it.

 

I have ensured the alternative subject name is correct and all printer name fields on the printer line up.

 

Any help would be much appreciated,

 

thanks

1 Accepted Solution

Accepted Solutions

mrjelly
Level 1
Level 1

ISE was not able to lookup the name using an LDAP external identity.

This was changed to an Active Directory Identity Source, in addition the certificate authentication was changed to look for any SAN name.

This is now working

 

Printer was Ricoh

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

what ISE version ?

Is this worked before you are setting first time ?

where do you see this error ?  on ISE Live Logs ?

is the Issue with Printers ? (does Printers support  MAB or 802.1X authentication ?)  

Subject not found in the applicable identity store(s)  - as per the logs your trying to setup authentication the device not found in the identity store you looking in LDAP/AD group.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

mrjelly
Level 1
Level 1

ISE was not able to lookup the name using an LDAP external identity.

This was changed to an Active Directory Identity Source, in addition the certificate authentication was changed to look for any SAN name.

This is now working

 

Printer was Ricoh

Review Cisco Networking for a $25 gift card