Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

HTTP Error 403 - Forbidden on Cisco ISE and SCEP RA

Dear Experts,

We are in process of deploying ISE 1.2 in our environment for BYOD.

The initial step of this process is to configure ISE as an SCEP Proxy and it requires certain configuration on the local CA. We have done all the required configurations on the local CA server.

Now, when we try to connect ISE with the local CA using SCEP RA Profiles, it gives "HTTP Error 403 - Forbidden". The URL we are using is http://ipaddress/certsrv/mscep/mscep.dll.

It seems that the local CA is not letting the ISE access the mscep.dll file. Now I dont understand how to allow ISE to access this file or the url. Please advise if there is any step by step process guide. Although, I have followed the ones from Cisco but it doesn't state how to give ISE the required rights for accessing mscep.dll.

Thanks in advance.

Jay

3 REPLIES
Cisco Employee

HTTP Error 403 - Forbidden on Cisco ISE and SCEP RA

Jay,

You should use this URL:

https://ipaddress/certsrv/mscep

If you try to get the cert from an http address, you will get an error.  You should be using https.  Also, the mscep.dll should not be part of the URL.

SCEP1.GIF

You can test this connectivity from any browser by putting that URL in the sddress bar.  You should see a page similar to this:

SCEP2.GIF

Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.  Otherwise, feel free to post follow-up questions.

Charles Moreton

New Member

HTTP Error 403 - Forbidden on Cisco ISE and SCEP RA

Charles,

Thanks for your reply.

However, if I use https://ipaddress/certsrv/mscep then I get this error.

SCEP Error.png

Also, If I type this on the URL using https then I get 500 - Internal Server Error. And If I do it using http then I get 403 - Forbidden Access is denied.

Cisco Employee

HTTP Error 403 - Forbidden on Cisco ISE and SCEP RA

Jay,

You may want to check the NDES settings on the CA Server.

497
Views
5
Helpful
3
Replies
CreatePlease to create content