cancel
Showing results for 
Search instead for 
Did you mean: 

wildcard/SAN certs with Junos Pulse

SF_Dan_
Frequent Contributor

wildcard/SAN certs with Junos Pulse

does the Pulse client not support SAN certs? I have a SAN cert installed and network connect works fine but Pulse says the certificate chain is not complete. I have already installed the intermediate in the IVE.

Thanks,

Dan

12 REPLIES 12
Russ_
Contributor

Re: wildcard/SAN certs with Junos Pulse

I installed version 7.1R1 and I'm still experiencing the same issue...

Russ_
Contributor

Re: wildcard/SAN certs with Junos Pulse

Ok, 7.1R1 does actually work with client certificates that use a chain.  As long as your certificate restriction is set at the Realm level.  I had mine set at the Role level and that does not work.  

Russ

rvi_
Occasional Contributor

Re: wildcard/SAN certs with Junos Pulse

ensure to bind device cert to internal network interface on the sa device cfg

Kita_
Valued Contributor

Re: wildcard/SAN certs with Junos Pulse

Hello Dan,

If the proper intermediate CA are installed on the IVE, you should not be getting any chaining errors. The other possiblity is the root CA is missing from the device. If you are using a VeriSign certificate, you may want to double check with them as their hierarchy has changed directly to a four-tier hierarchy (two intermediates) plus it is cross-certified by two root ca (which can be a bit confusing).

SF_Dan_
Frequent Contributor

Re: wildcard/SAN certs with Junos Pulse

The proper root and the 1 intermediate cert exists on the IVE and still no luck. Like I said, Network connect has no issues with the cert so not sure what is happening.

SF_Dan_
Frequent Contributor

Re: wildcard/SAN certs with Junos Pulse

Thawte's website has a troubleshooting tool that says my chain is incomplete also so I guess I have an issue with the intermediate cert I installed.

GeorgeGil_
New Contributor

Re: wildcard/SAN certs with Junos Pulse

Pulse client seems to have issues with wildcard certs... oh well. There goes another good Juniper idea poorly executed...

DirectAccess here I come!

SF_Dan_
Frequent Contributor

Re: wildcard/SAN certs with Junos Pulse

ya, kind of regreting going to pulse over network connect, it seems to be a beta product. I have checked everything and the entire chain exists, I guess I will try calling support.

MvdH25_
Occasional Contributor

Re: wildcard/SAN certs with Junos Pulse

same issue here...

We have a digicert wildcard certificate and the chain is fully correct!

Only thing complaining is Pulse..

Because it's just cosmetic (and I have enough to do) I'm simply afraid to call JTAC (again...)....all they will do is ask you for logs...logs...logs....Smiley Sad