<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does ACS 4.2 support IPSec template certificates? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573949#M311442</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is from the certificate:&lt;/P&gt;&lt;P&gt;EKU = IP security IKE intermediate (1.3.6.1.5.5.8.2.2)&lt;/P&gt;&lt;P&gt;KU = Digital Signature, Key Encipherment (a0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how to ensure that the EKU is Client Authentication and KU is Digital signature,&lt;BR /&gt;Key Encipherment and Data encipherment.&amp;nbsp; I don't see in the software that is generating the certReq anything about specifying the type of certificate that is needed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how the Windows Server 2003 CA determines what certificate template to use when returning a certificate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Nov 2010 01:47:43 GMT</pubDate>
    <dc:creator>aleary</dc:creator>
    <dc:date>2010-11-12T01:47:43Z</dc:date>
    <item>
      <title>Does ACS 4.2 support IPSec template certificates?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573947#M311425</link>
      <description>&lt;P&gt;I have ACS 4.2 124.12 cumulative patches installed.&amp;nbsp; I have enable EAP-FAST in ACS.&amp;nbsp; The CA is selected in the trusted list.&amp;nbsp; When I try to authenticate with the ACS I get a rejection.&amp;nbsp; Wireshark shows in the challenge that this is a 'unsupported Certificate'.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;In the AUTH.log I get the following where the failure occurs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri; "&gt;AUTH 11/04/2010 12:01:44 I 0000 46564 0x95 CryptoLib.SSLConnection.pvServerInfoCB - Process TLS data: SSL state=SSLv3 read client certificate B&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri; "&gt;AUTH 11/04/2010 12:01:44 I 2009 46564 0x95 EAP: EAP-FAST: Handshake failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri; "&gt;AUTH 11/04/2010 12:01:44 E 2255 46564 0x95 EAP: EAP-FAST: ProcessResponse: SSL send alert fatal:unsupported certificate&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri; "&gt;AUTH 11/04/2010 12:01:44 E 2258 46564 0x95 EAP: EAP-FAST: ProcessResponse: SSL ext error reason: b2 (Ext error code = 0)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri; "&gt;AUTH 11/04/2010 12:01:44 E 2297 46564 0x95 EAP: EAP-FAST: ProcessResponse(1519): mapped SSL error code (3) to -2120&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="font-style: background-color: #f8fafd;; "&gt;&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificate template is IPSec (Offline request) (IPSECIntermediateOffline).&amp;nbsp; Is there some configuration that I am not aware of?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573947#M311425</guid>
      <dc:creator>aleary</dc:creator>
      <dc:date>2019-03-11T00:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does ACS 4.2 support IPSec template certificates?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573948#M311430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As it reporting error on client certifcate, Check the client cert, client cert must&lt;BR /&gt;have the following: EKU = Client Authentication, KU = Digital signature,&lt;BR /&gt;Key Encipherment and Data encipherment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 01:25:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573948#M311430</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-11-12T01:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Does ACS 4.2 support IPSec template certificates?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573949#M311442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is from the certificate:&lt;/P&gt;&lt;P&gt;EKU = IP security IKE intermediate (1.3.6.1.5.5.8.2.2)&lt;/P&gt;&lt;P&gt;KU = Digital Signature, Key Encipherment (a0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how to ensure that the EKU is Client Authentication and KU is Digital signature,&lt;BR /&gt;Key Encipherment and Data encipherment.&amp;nbsp; I don't see in the software that is generating the certReq anything about specifying the type of certificate that is needed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how the Windows Server 2003 CA determines what certificate template to use when returning a certificate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 01:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573949#M311442</guid>
      <dc:creator>aleary</dc:creator>
      <dc:date>2010-11-12T01:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Does ACS 4.2 support IPSec template certificates?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573950#M311473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the&lt;/P&gt;&lt;P&gt;EKU : &lt;STRONG&gt;&lt;A class="jive-link-external-small" href="http://tinyurl.com/2dakmaw"&gt;http://tinyurl.com/2dakmaw&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;KU = &lt;STRONG&gt;&lt;A class="jive-link-external-small" href="http://tinyurl.com/2aqjecq"&gt;http://tinyurl.com/2aqjecq&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;On the below URL refer to the&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3 class="p_H_Head3"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;6.4.1 Obtaining the Client-Side Certificate &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;H3 class="p_H_Head3"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a008009256b.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a008009256b.shtml&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/H3&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 02:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573950#M311473</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-11-12T02:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Does ACS 4.2 support IPSec template certificates?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573951#M311493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hi Anthony, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;did you find any solution for this issue? As I am now in exatly the same situation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 14:16:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573951#M311493</guid>
      <dc:creator>pnavratil</dc:creator>
      <dc:date>2011-04-11T14:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Does ACS 4.2 support IPSec template certificates?</title>
      <link>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573952#M311524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pavel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After working with Albert Sun and Igal Katz we found that IOS does not support EKU - extended Key Usage where types of certificate can be specified.  So in the cert request,  we won't specify any EKU.  For EKU aware CA, like ACS or MS CA, it considers it as IPSEC certificate request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an enhancement by the PKI team to add support for EKU (Enhanced Key Usage).  Not sure of the official enhancement name (EKU for IOS).  This enhancement has to be implemented before we can externally authenticate LSC certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 16:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/does-acs-4-2-support-ipsec-template-certificates/m-p/1573952#M311524</guid>
      <dc:creator>aleary</dc:creator>
      <dc:date>2011-04-13T16:35:06Z</dc:date>
    </item>
  </channel>
</rss>

