<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate selection  on NAM in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091262#M25489</link>
    <description>&lt;P&gt;HI team ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a query regarding the &amp;nbsp;certificate selection on the NAM &amp;nbsp;while using the EAP-TLS( User and machine auth with cert ).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a setup where i am using EAP-TLS authentication with user and machine authentication done with certificate .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way in anyconnect that i can specify which certificate to be used for the authentication rather than NAM Pop up&amp;nbsp;for certificate selection .&lt;/P&gt;
&lt;P&gt;I want the certificate selection to be automated without any manual task&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thnx&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dibu&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:55:38 GMT</pubDate>
    <dc:creator>Diburaj kp</dc:creator>
    <dc:date>2019-03-11T07:55:38Z</dc:date>
    <item>
      <title>Certificate selection  on NAM</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091262#M25489</link>
      <description>&lt;P&gt;HI team ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a query regarding the &amp;nbsp;certificate selection on the NAM &amp;nbsp;while using the EAP-TLS( User and machine auth with cert ).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a setup where i am using EAP-TLS authentication with user and machine authentication done with certificate .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way in anyconnect that i can specify which certificate to be used for the authentication rather than NAM Pop up&amp;nbsp;for certificate selection .&lt;/P&gt;
&lt;P&gt;I want the certificate selection to be automated without any manual task&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thnx&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dibu&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091262#M25489</guid>
      <dc:creator>Diburaj kp</dc:creator>
      <dc:date>2019-03-11T07:55:38Z</dc:date>
    </item>
    <item>
      <title>Not that I have used this,</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091263#M25491</link>
      <description>&lt;P&gt;Not that I have used this, but perhaps AnyConnect 4.5 certificate pinning would help in your situation?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect45/administration/guide/b_AnyConnect_Administrator_Guide_4-5/configure-vpn.html#concept_cbg_1cj_rz"&gt;https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect45/administration/guide/b_AnyConnect_Administrator_Guide_4-5/configure-vpn.html#concept_cbg_1cj_rz&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 17:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091263#M25491</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2017-08-10T17:45:50Z</dc:date>
    </item>
    <item>
      <title>Thanks Rob for the swift</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091264#M25493</link>
      <description>&lt;P&gt;Thanks Rob for the swift reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Certificate pinning option is available for the Wireless EAP-TLS configuration &amp;nbsp;or only available for VPN .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also will the "&amp;nbsp;&lt;STRONG&gt;Use&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;certificate matching rule "&amp;nbsp;&lt;/STRONG&gt; option under the Network &amp;gt; credential help to get the correct certificate automatically .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thnx&lt;/P&gt;
&lt;P&gt;Dibu&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 09:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091264#M25493</guid>
      <dc:creator>Diburaj kp</dc:creator>
      <dc:date>2017-08-11T09:39:48Z</dc:date>
    </item>
    <item>
      <title>If you choose EAP-TLS as the</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091265#M25494</link>
      <description>&lt;P&gt;If you choose EAP-TLS as the authentication mechanism, the NAM profile editor should give you the certificate/credential selection option. I believe this forces the client certificate selection to be automatic. I have not tested this with NAM, but a similar setting for VPN works the same way.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 18:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091265#M25494</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-08-11T18:34:36Z</dc:date>
    </item>
    <item>
      <title>Hi all</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091266#M25495</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have got the solution .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Use&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;certificate matching rule "&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option under the Network &amp;gt; credential&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Write a rule to match the attribute for the required argument &amp;nbsp;ie cn or issuer.dc etc .&lt;/P&gt;
&lt;P&gt;This instructs anyconnect to search only for the specific certificate and hence user will not be asked to select for the certificate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Certificate pin option is available only for vpn from 4.5 version onwards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks all for the help .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thnx&lt;/P&gt;
&lt;P&gt;Dibu&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 00:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-selection-on-nam/m-p/3091266#M25495</guid>
      <dc:creator>Diburaj kp</dc:creator>
      <dc:date>2017-08-15T00:39:06Z</dc:date>
    </item>
  </channel>
</rss>

