<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User authentication with certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-authentication-with-certificates/m-p/251044#M434883</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Following sceniario: user with certificate doing a vpn to vpn concentrator or pix. Authentication is made on ACS 3.2(2).&lt;/P&gt;&lt;P&gt;VPN users are using certificates for authentication.&lt;/P&gt;&lt;P&gt;When they connect, the certificate is asimilated with group in vpn conc. or pix. There is no user authentication. I believe should be some user authentication in ACS. Group in vpn conc. is made by the book, but i can't find any option to authenticate user certificate against ACS (second time, i whould say - first time vpn conc. check the certificate). Am i loosing something from this scenario? I need user authentication against ACS for accounting.&lt;/P&gt;&lt;P&gt;10x&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:39:29 GMT</pubDate>
    <dc:creator>8dstaicu</dc:creator>
    <dc:date>2019-03-10T14:39:29Z</dc:date>
    <item>
      <title>User authentication with certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-with-certificates/m-p/251044#M434883</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Following sceniario: user with certificate doing a vpn to vpn concentrator or pix. Authentication is made on ACS 3.2(2).&lt;/P&gt;&lt;P&gt;VPN users are using certificates for authentication.&lt;/P&gt;&lt;P&gt;When they connect, the certificate is asimilated with group in vpn conc. or pix. There is no user authentication. I believe should be some user authentication in ACS. Group in vpn conc. is made by the book, but i can't find any option to authenticate user certificate against ACS (second time, i whould say - first time vpn conc. check the certificate). Am i loosing something from this scenario? I need user authentication against ACS for accounting.&lt;/P&gt;&lt;P&gt;10x&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-with-certificates/m-p/251044#M434883</guid>
      <dc:creator>8dstaicu</dc:creator>
      <dc:date>2019-03-10T14:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: User authentication with certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/user-authentication-with-certificates/m-p/251045#M434884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm going to make a blind stab at this as I don't fully understand your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certficates are used to authenticate the VPN client (the software) more so than the user.  ACS does not provide certificate authentication.  The CA provides validation of the certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like the Pix to authenticate a username/password in addition to checking the certificate for accounting purposes, then you'll need to use this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map map-name client authentication aaa-server-name &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will make the Pix to authentication of all dynamic VPN clients against the ACS server.  It won't provide true accounting though.  For that, you must configure the global [aaa authentication] and [aaa accounting] on the Pix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2004 03:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-authentication-with-certificates/m-p/251045#M434884</guid>
      <dc:creator>shannong</dc:creator>
      <dc:date>2004-02-09T03:31:42Z</dc:date>
    </item>
  </channel>
</rss>

