<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I believe this is correct, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-basic-certificate-checking/m-p/3092187#M25462</link>
    <description>&lt;P&gt;I believe this is correct, ISE just does checks the certificates for the steps you have mentioned. I think the only other &amp;nbsp;"basic check" it does is the client certificate KU and EKU settings, basically to check if the certificate presented is meant for that purpose or not. "Client authentication" is a required setting for EKU (if explicitly set) for the client certificate presented to ISE.&lt;/P&gt;</description>
    <pubDate>Sun, 13 Aug 2017 11:45:13 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2017-08-13T11:45:13Z</dc:date>
    <item>
      <title>ISE Basic Certificate Checking</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-basic-certificate-checking/m-p/3092186#M25461</link>
      <description>&lt;P&gt;In reference to setting up a Certificate Authentication Profile ...&lt;/P&gt;
&lt;P&gt;I see that "basic certificate checking" does not require an identity source.&amp;nbsp; I'm wanting to ensure I know what "basic certificate checking" means.&amp;nbsp; My assumption is the all that is checked is:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1) Was the cert issued by a Trusted CA?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Has the cert expired? Has a valid/current date&lt;/P&gt;
&lt;P&gt;3) Has the cert been revoked?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My take on this is if I have machine certs issued by some Root CA (not my AD) then I could use the basic checking to verify that the cert was issued by the appropriate CA (I've installed the Trusted Root Cert on my ISE) and was therefore a trusted device for EAP-FAST/EAP-TLS machine authentication purposes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is this correct?&amp;nbsp;&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:56:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-basic-certificate-checking/m-p/3092186#M25461</guid>
      <dc:creator>cbradt</dc:creator>
      <dc:date>2019-03-11T07:56:02Z</dc:date>
    </item>
    <item>
      <title>I believe this is correct,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-basic-certificate-checking/m-p/3092187#M25462</link>
      <description>&lt;P&gt;I believe this is correct, ISE just does checks the certificates for the steps you have mentioned. I think the only other &amp;nbsp;"basic check" it does is the client certificate KU and EKU settings, basically to check if the certificate presented is meant for that purpose or not. "Client authentication" is a required setting for EKU (if explicitly set) for the client certificate presented to ISE.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2017 11:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-basic-certificate-checking/m-p/3092187#M25462</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-08-13T11:45:13Z</dc:date>
    </item>
  </channel>
</rss>

