<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migrating EAP-MSCHPv2 to EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/migrating-eap-mschpv2-to-eap-tls/m-p/2067462#M157597</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default ACS has peap and eap-tls authentication enabled and is part of the proposed eap types. Just remember that the certificate will have to uploaded to the ACS trusted certificate store, and once you configure the certificate authentication profile, you can map that into a Identity Sequence store, so that ACS will check the cert, and if one isnt provided it can fall back to password authenticate against AD.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Tarik Admani&lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Oct 2012 19:20:48 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-10-26T19:20:48Z</dc:date>
    <item>
      <title>Migrating EAP-MSCHPv2 to EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-eap-mschpv2-to-eap-tls/m-p/2067461#M157574</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer who has deployed ACS for 802.1x against active directory for their wired Cisco switch infrastructure using EAP-MSCHAPv2. Now they would like to change to EAP-TLS but if they just switch the client PCs would be locked out and could get a certificate pushed out to them from AD.&lt;/P&gt;&lt;P&gt;Can ACS be set to allow both autentication methods during the migration phase ? I know it supports negotiation of the EAP type but its a while since I played with ACS and dont have one to hand to try it with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-eap-mschpv2-to-eap-tls/m-p/2067461#M157574</guid>
      <dc:creator>Patrick Colbeck</dc:creator>
      <dc:date>2019-03-11T02:43:36Z</dc:date>
    </item>
    <item>
      <title>Migrating EAP-MSCHPv2 to EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-eap-mschpv2-to-eap-tls/m-p/2067462#M157597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default ACS has peap and eap-tls authentication enabled and is part of the proposed eap types. Just remember that the certificate will have to uploaded to the ACS trusted certificate store, and once you configure the certificate authentication profile, you can map that into a Identity Sequence store, so that ACS will check the cert, and if one isnt provided it can fall back to password authenticate against AD.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Tarik Admani&lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2012 19:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-eap-mschpv2-to-eap-tls/m-p/2067462#M157597</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-26T19:20:48Z</dc:date>
    </item>
  </channel>
</rss>

