<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Could you please confirm the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045941#M24082</link>
    <description>&lt;P&gt;Could you please confirm the&amp;nbsp;following :&lt;/P&gt;
&lt;P&gt;1) Are you talking about CN to to be check during user authentication in ISE.&lt;/P&gt;
&lt;P&gt;2) Looking for where endpoint-user certificate is present in ISE.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2017 18:24:09 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2017-02-08T18:24:09Z</dc:date>
    <item>
      <title>Cisco ISE Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045940#M24081</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;is there any possibility how to create a report in ISE (1.1.4.218 or 1.4.0.253) where I can display the the "Issuer - Common Name" of the client/user-certificate?&lt;/P&gt;
&lt;P&gt;Thank you very much in advance!&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Manuel&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045940#M24081</guid>
      <dc:creator>msporleder</dc:creator>
      <dc:date>2019-03-11T07:26:45Z</dc:date>
    </item>
    <item>
      <title>Could you please confirm the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045941#M24082</link>
      <description>&lt;P&gt;Could you please confirm the&amp;nbsp;following :&lt;/P&gt;
&lt;P&gt;1) Are you talking about CN to to be check during user authentication in ISE.&lt;/P&gt;
&lt;P&gt;2) Looking for where endpoint-user certificate is present in ISE.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 18:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045941#M24082</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-08T18:24:09Z</dc:date>
    </item>
    <item>
      <title>Hello Gagan,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045942#M24083</link>
      <description>&lt;P&gt;Hello Gagan,&lt;/P&gt;
&lt;P&gt;sorry for replying so late.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I am talking about the Common Name of the issuer of&amp;nbsp;a client-certificate. &lt;BR /&gt;Like: This client-certificate was issued by&amp;nbsp;CA ???&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Manuel&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 13:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045942#M24083</guid>
      <dc:creator>msporleder</dc:creator>
      <dc:date>2017-02-14T13:54:14Z</dc:date>
    </item>
    <item>
      <title>Yes, ISE has the capability</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045943#M24084</link>
      <description>&lt;P&gt;Yes, ISE has the capability to fetch just the CN of the certificate and take it to AD for checking the user authentication.&lt;/P&gt;
&lt;P&gt;Also there is a binary comparison of certificate received from client and match it with certificate present in AD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Administration &amp;gt; Identity &amp;gt; External identity store &amp;gt; Certificate authentication profile.&lt;/P&gt;
&lt;P&gt;Hope it answers you query!!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS : rate if it helps!!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 16:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045943#M24084</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-14T16:23:58Z</dc:date>
    </item>
    <item>
      <title>Hello Gagan,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045944#M24085</link>
      <description>&lt;P&gt;Hello Gagan,&lt;/P&gt;
&lt;P&gt;I know that the ISE has all the informations. But I dont see any chance to create a custom report where I can filter for the CN of the client-certificate-issuer.&lt;/P&gt;
&lt;P&gt;And this is what I would like to do.&lt;/P&gt;
&lt;P&gt;Or to have a column in the&amp;nbsp;live authentications where I can filter for that attribute.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I did as a workaroung: I created&amp;nbsp;many authorization-rules where I also ask for the attribute "&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;CERTIFICATE:Issuer - Common Name" and then as the result I&amp;nbsp;crated different&amp;nbsp;authorization profiles (basically all with the same attribute details but with different names).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;So now I can filter on the name of the authorization profiles...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;But from my point of view this is not a good way to handle this.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;Especially all the informations are in the systems database, only I can not create a report where I can ask for all attributes I'd like to.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="widgetContainer" dojoattachpoint="widgetContainer"&gt;&lt;SPAN title="EAP-TLS AND CERTIFICATE:Subject - Common Name ENDS_WITH vwos.vw.vwg AND InternalUser:IdentityGroup CONTAINS 60 AND CERTIFICATE:Issuer - Common Name EQUALS VW-CA-802x-02 " class="conditionsViewClass"&gt;Regards&lt;BR /&gt;Manuel&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 09:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045944#M24085</guid>
      <dc:creator>msporleder</dc:creator>
      <dc:date>2017-02-15T09:13:05Z</dc:date>
    </item>
    <item>
      <title>Hi Manuel,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045945#M24087</link>
      <description>&lt;P&gt;Hi Manuel,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know there is no option in live reports for specific search on&amp;nbsp;CN. However if you open any live authentication for AD authentication. You'll find CN resolved identities in report.&lt;/P&gt;
&lt;P&gt;Let me know of any queries on this...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS : rate if it helps!!!!!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 03:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reports/m-p/3045945#M24087</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-17T03:09:19Z</dc:date>
    </item>
  </channel>
</rss>

