<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.2 - Authorization Policy for Digital Certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308774#M135272</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to upload all certificates (intermediate and root) that are used to sign the client cert into the ISE CA database. You will also have to make sure that checkbox for trust for client authentication is checked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Aug 2013 03:55:50 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2013-08-16T03:55:50Z</dc:date>
    <item>
      <title>ISE 1.2 - Authorization Policy for Digital Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308772#M135189</link>
      <description>&lt;P&gt;Hi Everyone. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Cisco Ise 1.2 when I created authorization Policy rule for PEAP(MSCHAPv2) and the ISE can match on the rule e permit based on AuthProfile. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT, authentications using digital certificates (EAP_TLS) I can´t do some AuthorizationPolicy for match. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´m try some: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px; background-color: #ffffff;"&gt;if &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;any &lt;/P&gt;&lt;P&gt; &lt;STRONG style="color: #000000; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px; background-color: #ffffff;"&gt;AND &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;authEAPprot: EAP-TLS &lt;/P&gt;&lt;P&gt; &lt;STRONG style="color: #000000; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px; background-color: #ffffff;"&gt;AND &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Certificate:inssue : iqual : CA-root &lt;/P&gt;&lt;P&gt; &lt;STRONG style="color: #000000; font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 16px; background-color: #ffffff;"&gt;THEN &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ACCESS_FULL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Operations&amp;gt;Authetications I can see the authentication and when I open the details, I can see the method is EAP-TLS BUT my rule is not correct cuz&lt;SPAN style="font-size: 10pt;"&gt; authorization policy that use is &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt;"&gt;Default.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Someone can do some Tip about How i can make this rule for authentications that use EAP-TLS (digital certificates)???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308772#M135189</guid>
      <dc:creator>Tiago Andrade de Paula</dc:creator>
      <dc:date>2019-03-11T03:46:47Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 - Authorization Policy for Digital Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308773#M135211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, it just sounds like it's not matching your rule, try removing the certificate issuer = CA-root condition and see what happens. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that if you use equals as operator, it has to match exactly including case, what your certfificate have written in the certificate issuer field you are using.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 19:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308773#M135211</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2013-08-15T19:29:11Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 - Authorization Policy for Digital Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308774#M135272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to upload all certificates (intermediate and root) that are used to sign the client cert into the ISE CA database. You will also have to make sure that checkbox for trust for client authentication is checked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 03:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-authorization-policy-for-digital-certificates/m-p/2308774#M135272</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-16T03:55:50Z</dc:date>
    </item>
  </channel>
</rss>

