> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/de/andere/troubleshooting/cisco-ise-host-header-limitation.md).

# Cisco-ISE-Host-Header-Einschränkung

Sowohl Cisco ISE als auch Aruba ClearPass (nur bis einschließlich **ClearPass 6.9.5**) unterstützen HTTP 1.1 beim Abrufen von OCSP nicht und senden in ihrer OCSP-Anfrage keinen Host-Header. Das liegt wahrscheinlich daran, dass OpenSSL bis Version 1.0.2, das offenbar im Backend verwendet wird, [einen zusätzlichen Parameter erforderte, um den Host-Header für OCSP-Anfragen zu senden](https://github.com/openssl/openssl/issues/1986), während OpenSSL 1.1.0, veröffentlicht im August 2016, dies automatisch tut. Daher können sie keine Verbindung zu einer allgemeinen SCEPman-Instanz herstellen, die auf Azure App Services ausgeführt wird. Die Fehlermeldung kann folgendermaßen aussehen:

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-73190ac3e2e77c25974776ffa48e74b2c33f96da%2Fcisco-ocsp-error%20\(2\)%20\(4\)%20\(4\)%20\(4\)%20\(4\)%20\(4\)%20\(2\)%20\(1\).jpg?alt=media)

Cisco untersucht derzeit zukünftige Verbesserungen, aber vorerst können Sie ein [Azure Application Gateway](https://azure.microsoft.com/en-us/services/application-gateway/) verwenden, um eine SCEPman-Instanz bereitzustellen, die keinen Host-Header benötigt.

Die folgenden Anweisungen beschreiben die Schritte zum Erstellen eines Azure Application Gateway für SCEPman:

## 1) Erstellen Sie ein neues Application Gateway

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-a402724c716fac522d61e03233aff4e96a90e2f4%2Fscreen-shot-2019-10-18-at-17.12.40%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(1\).png?alt=media)

## 2) Geben Sie die erforderlichen grundlegenden Informationen an

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-367c46f5958d85d0c7d98e7b4691bd93add555ae%2Fscreen-shot-2019-10-18-at-17.13.55%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\).png?alt=media)

## 3) Erstellen Sie eine neue statische öffentliche IP-Adresse

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9f24e6ff6ca4195383c78bbb74ca1e3afae92a2c%2Fscreen-shot-2019-10-18-at-17.14.19%20\(2\)%20\(4\)%20\(5\)%20\(5\)%20\(5\)%20\(2\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(3\)%20\(8\).png?alt=media)

## 4) Erstellen Sie einen neuen Backend-Pool und verweisen Sie ihn auf Ihren SCEPman App Service

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-4e763c48bd1ccfd3326d7a86ec2573e68f25b3a1%2Fscreen-shot-2019-10-18-at-17.14.55%20\(2\)%20\(4\)%20\(5\)%20\(2\).png?alt=media)

{% hint style="info" %}
Im geo-redundanten Szenario müssen Sie beide SCEPman-App-Services dem Backend-Pool hinzufügen.
{% endhint %}

## 5) Fügen Sie eine Routingregel für HTTP hinzu

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-fe2deec114610507ba0c0133a4270b8d9502eeda%2Fscreen-shot-2019-10-18-at-17.15.36%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\).png?alt=media)

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-66becdc39468a7feb2cfbef12b2bd65ad8f34c35%2FReplace5.png?alt=media)

## 5b) Fügen Sie eine neue HTTP-Einstellung mit Host-Header hinzu (Ihr öffentlicher FQDN von SCEPman)

{% hint style="warning" %}
Anfang Juni führte Microsoft einen Fehler im Azure Application Gateway ein, der verhindert, einem Host-Header-freien Request einen Host-Header hinzuzufügen, wenn "Pick host name from backend target" ausgewählt ist. In einer früheren Version dieser Dokumentation haben wir "Pick host name from backend target" empfohlen, aber das funktioniert nicht mehr. Als Workaround wählen Sie wie unten dargestellt "Override with specific domain name" und fügen Sie den Namen Ihres SCEPman App Service ein, z. B. *contoso-scepman.azurewebsites.net*.
{% endhint %}

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9cfce9cc03543f0741deb930dda57ee46cfc487e%2Fscreen-shot-2019-10-18-at-17.16.21%20\(1\)%20\(1\)%20\(2\)%20\(4\)%20\(3\)%20\(1\).png?alt=media)

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-2a9b2259c01bf0b04c56de7c104bb9b841448513%2FReplace5b2.png?alt=media)

## 6) Optional: Fügen Sie eine Routingregel für HTTPS hinzu

{% hint style="warning" %}
Dieser Schritt erfordert ein HTTPS-Webserverzertifikat.
{% endhint %}

{% hint style="info" %}
Die Verwendung von HTTP ohne TLS ist keine Sicherheitslücke; PKI-basierte Ressourcen werden üblicherweise über HTTP ohne TLS veröffentlicht, da der TLS-Handshake möglicherweise Zugriff auf diese Ressourcen erfordert. Die Verwendung von TLS würde ein Henne-Ei-Problem erzeugen, bei dem der TLS-Handshake Zugriff auf die PKI-Ressourcen erfordert und der Zugriff auf die PKI-Ressourcen einen TLS-Handshake erfordert. Daher verwenden diese PKI-Ressourcen, einschließlich der Protokolle SCEP und OCSP, dort, wo es erforderlich ist, ihre eigene Verschlüsselung und/oder Signaturen.
{% endhint %}

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-61115b6a2a67ab4be644da31ceae6817dc9555a1%2FReplace61.png?alt=media)

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9535788b316a6ca84de9606e7c218a9a7d3078c0%2Fscreen-shot-2019-10-18-at-17.17.44%20\(2\)%20\(4\)%20\(3\).png?alt=media)

## 6b) Fügen Sie eine neue HTTPS-Einstellung mit Host-Header hinzu (Ihr öffentlicher FQDN von SCEPman)

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FowpbgDoNuM7dKtGKGxsO%2F2024-06-06%2016_52_56-.png?alt=media&amp;token=ca795e9c-c7d5-445f-ad66-5f1c21f3119c" alt=""><figcaption></figcaption></figure>

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-92a1c1e3bb6cabf50ff4385faa0262b62ba48f80%2FReplace62.png?alt=media)

## 7) Bestätigen Sie die Routingregeln

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-f71ff2eac67cf28c1e5a8dd4357932609821eff6%2Fscreen-shot-2019-10-18-at-17.18.56%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(2\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\).png?alt=media)

## 8) Schließen Sie die Konfiguration des Application Gateway ab

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-5fedc198773af98b0271c069470a71093d850b33%2Fscreen-shot-2019-10-18-at-17.19.13%20\(2\)%20\(4\)%20\(3\)%20\(1\).png?alt=media)

## 9) Konfigurieren Sie den DNS-Namen für die IP

Fügen Sie dann einen DNS-Namen für das Gateway hinzu:

1. Öffnen Sie die IP-Adressressource
2. Fügen Sie einen Namen Ihrer Wahl als DNS-Namensbezeichnung hinzu

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-baaec006f5aac20c38fb1ed18a464e4849845770%2Fip-address.png?alt=media)

Optional: Sie können in Ihrem eigenen DNS-Server einen CNAME-Eintrag für den DNS-Namen hinzufügen.

{% hint style="info" %}
Im geo-reduzierten Szenario können Sie in Cisco ISE weiterhin die benutzerdefinierte SCEPman-Domain-URL (die auf den Traffic Manager verweist) und die URL des Application Gateway als OCSP-Responder verwenden.
{% endhint %}

{% hint style="info" %}
Die OCSP-Responder-URL wäre: `http://<Application-Gateway-URL>/ocsp`

**Hinweis:** Die OCSP-Responder-URL sollte HTTP und nicht HTTPS sein, siehe [hier](https://docs.scepman.com/de/andere/troubleshooting/pages/86ebde45c4ddad114e012372246f2e55c35870d6#id-21.-can-https-only-be-enabled)
{% endhint %}

## Intune/JAMF-Konfiguration

In der Intune-Konfiguration können Sie weiterhin die URL des App Service anstelle der URL des Azure Application Gateway verwenden. Wenn Sie dies tun, kommunizieren die Clients direkt mit dem App Service. Sie müssen die URL des Azure Application Gateway in Cisco ISE konfigurieren, da nur diese URL HTTP-1.0-Anfragen unterstützt.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/de/andere/troubleshooting/cisco-ise-host-header-limitation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
