cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
757
Views
0
Helpful
5
Replies

Renewal Certificate ISE

dungtran.90
Level 1
Level 1

Dear All

 

I have a case below:

 

I have an ISE node. EAP certificate is expired so I renewal it and received the certificate from Zone which is using normal for other sites ( Europe, India, America..) But in Vietnam, we met the issue as the picture below. We change the EAP certificate from Comodo to Sectigo. Import successfully to ISE, a client can connect now, but it does not automatically connect anymore, every time we move to another AP we need to click connect twice.

 

One.JPG

 

Could you please help or support?

Thanks

DungTran

5 Replies 5

patoberli
VIP Alumni
VIP Alumni
Do you have more than one Radius server configured? If yes, do both use the same root certificate / issuer of the certificate?
If not, then this is the normal behavior.
Make sure that the certificate shown to the client is actually the correct one and not a Man in the Middle attack with a rogue access point.

"show certificate details" may guide you to the root cause

possibilities:

- the host-name does not match the name in the certificate

  this would be immediately shown 

- when using multiple ISE servers , you may need to configure SAN names in the certificate
  certificate details -> alternate names

- you may have imported a certificate with incorrect certification-chaining

   certificate details -> certification path

ammahend
VIP
VIP

Some additional basic checks ... 

verify Sectigo root cert chain in present on client.

On ISE end I am sure you check Sectigo root cert to be used for client authentication.

-hope this helps-

Dear Ammahend
Root cert already verified by Zone.
So in the ISE end, i need to enable: Trust for client authentication and Syslog ?
Thanks
DungTran

yes If you are using this certificate for client EAP auth. 

-hope this helps-
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card