cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1196
Views
5
Helpful
9
Replies

NAC SSL Certificates

Hello there,

I installed NAC and cutover to production env. without changing the perfigo root certificate. This is because i had no CA server.

Now i've got a win 2003 Standalone root CA Server configured. What is the impact on requesting certificate from this CA and install it on the NAC server and Manager?

regards,

Stanslaus.

9 Replies 9

Faisal Sehbai
Level 7
Level 7

Stanslaus,

No impact if you do it right. Details on adding a cert from 3rd party (in this case your own CA)

CAS: http://tinyurl.com/yju2jcy

CAM: http://tinyurl.com/yglhq3w

This is assuming 4.5

HTH,

Faisal

Thanks Faisal.

I have tried to access the links but i'm getting the bellow message from both URLs.

Forbidden File or Application

The file or application you are trying to access may require additional entitlement or you are trying to access a file with an invalid name. Additional entitlement levels are granted based on a users relationship with Cisco on a per-application basis.

If you feel you have reached this page in error, please try one of the following methods to locate your document:

1. If you are manually entering the URL into your browser location bar, be sure to include the file name of the page you are trying to access (file names typically end in .htm, .html or .shtml).

2. Use the Search feature located in the upper right section of this page.

3. Return to the Cisco.com Home or select a primary site area from the top navigation bar.

4. Consult with your Cisco Account Manager to confirm you have the appropriate entitlement to access this page.

If you would like to contact someone about this problem, please click on the Contacts & Feedback link below.

Clear your cookies in the browser and try again. I've seen that before and clearing cookies helps. If that still doesn't help let me know and I'll send you a PDF of the relevant portion

Faisal

Hi Faisal,

I've cleared cookies but no success. I've tried 3 different browsers also(Int expl, firefox and Epiphany) but ending up with the same message.

regards,

Stanslaus.

Stanslaus,

Within the URL try changing the word partner to customer and try again.

If that still doesn't work, email me and I'll send you the relevant portion in PDF

HTH,

Faisal

Hi Faisal,

I managed to install certificates from my internal CA Server and remove the perfigo certificate. The problem is that users are still required to accept the certificate everytime they login.

regards,

Stanslaus.

Stanslaus,

Is the root certificate (from the CA which issued the CAS/CAM certs) installed on the clients? If not, can you please install that root cert on the clients and try again?

HTH,

Faisal

Hello,

We have deployed a similar scenario and we solved this issue by installing an ID cert of every PC; the ID cert of course was issued by the same CA Authority used by the NAC Servers.

Hope it helps.

DL.

Hi Denis/Faisal,

I accessed the CA web from one of PCs giving the warning and found a place to install ceritficate chain ( written "To trust certificates issued from this certification authority, install this CA certificate chain."). I click install and it was successfully installed. The PC keeps on giving the warning. Is this the correct way of installing the root certificate on PC? If not please where can i find a guide on how to request the certificated from the CA?

Thanks.

Stanslaus.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: