April 10, 2013
NOTICE:
THIS FIELD NOTICE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTY OF MERCHANTABILITY. YOUR USE OF THE INFORMATION ON THE FIELD NOTICE OR MATERIALS LINKED FROM THE FIELD NOTICE IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS FIELD NOTICE AT ANY TIME.
Revision History
Revision Date Comment 1.0 10-APR-2013 Initial Public Release
Products Affected
Products Affected Comments Cisco Identity Services Engine (CISE) Software Versions 1.1.3 and earlier
Problem Description
Google Chrome is not a supported browser for use with the Administrative User Interface of the Identity Services Engine (ISE), Version 1.1.3 and earlier.
If an authenticated admin user uses Google Chrome to edit the Authorization Policy rules on the policy page, this might result in an incorrect order of policy rules; this incorrect order might impact authorization of end users.
This issue is limited to authenticated admin users with permissions to manage ISE polices. This issue does not apply to end users that use Chrome for web authentication for network access.
Background
In ISE Version 1.1.3 and earlier, use of Google Chrome to edit Authorization Policy rules when 11 or more rules exist might cause the policy rank to be incorrectly reordered. In order to restore the correct order, the Technical Assistance Center must execute SQL scripts on the affected ISE node.
Problem Symptoms
Ordinarily, Authorization Policy rules are in order above the default rule. After the rules are edited and saved, they are out of order and might even be below the default rule.
Workaround/Solution
Do not use Google Chrome with the ISE Administrative User Interface. If you have used Google Chrome and the symptoms described in this field notice are present, contact the Technical Assistance Center in order to correct the order of the Authorization Policy rules on the policy page and correct the associated database.
This is a list of supported Administrative User Interface browsers.
DDTS
To follow the bug ID link below and see detailed bug information, you must be a registered customer and you must be logged in.
DDTS Description CSCuc48613 (registered customers only) Google Chrome can cause re-ordering of Authorization Policy rules
For More Information
If you require further assistance, or if you have any further questions regarding this field notice, please contact the Cisco Systems Technical Assistance Center (TAC) by one of the following methods:
Receive Email Notification For New Field Notices
Cisco Notification Service—Set up a profile to receive email updates about reliability, safety, network security, and end-of-sale issues for the Cisco products you specify.