03-15-2024 11:49 PM
Hello,
I am getting an error with a printer authenticating with Cisco ISE for dot1x.
The error is "Subject not found in the applicable identity store(s)".
This is an LDAP identity lookup. It is looking for the alternative subject name DNS, and this is all being seen in the certificate, I can see this in the logs.
In the identity store, if I go to the attribute tab, I can find the printer there so ISE itself appears to be able to see it.
I have ensured the alternative subject name is correct and all printer name fields on the printer line up.
Any help would be much appreciated,
thanks
Solved! Go to Solution.
03-22-2024 02:13 AM - edited 03-22-2024 02:14 AM
ISE was not able to lookup the name using an LDAP external identity.
This was changed to an Active Directory Identity Source, in addition the certificate authentication was changed to look for any SAN name.
This is now working
Printer was Ricoh
03-16-2024 01:42 AM
what ISE version ?
Is this worked before you are setting first time ?
where do you see this error ? on ISE Live Logs ?
is the Issue with Printers ? (does Printers support MAB or 802.1X authentication ?)
Subject not found in the applicable identity store(s) - as per the logs your trying to setup authentication the device not found in the identity store you looking in LDAP/AD group.
03-22-2024 02:13 AM - edited 03-22-2024 02:14 AM
ISE was not able to lookup the name using an LDAP external identity.
This was changed to an Active Directory Identity Source, in addition the certificate authentication was changed to look for any SAN name.
This is now working
Printer was Ricoh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide