<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS and ECC ciphers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557765#M440696</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please elaborate how to prepare the ACS please. I am the person who ask Ben the original question for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this was RSA - I would place the RSA ca certificate up in the "User and Identity Stores" location and then create a CSR in the System Administration &amp;gt; Local Server Certificate &amp;gt; Local Certificates location, sign and complete the request in the Outstanding&amp;nbsp; Signing Requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am using ECC - I would place the ECC ca certificate at the User and Identity Stores location and then generate a CSR but I noticed that the key length (512, 1024, 2048, 4096) and hash digest (SHA1, SHA256) don't match attributes of ECC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank-you,&lt;/P&gt;&lt;P&gt;Chris &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 May 2017 01:45:41 GMT</pubDate>
    <dc:creator>chris-lawrence</dc:creator>
    <dc:date>2017-05-31T01:45:41Z</dc:date>
    <item>
      <title>ACS and ECC ciphers</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557763#M440694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;does anyone has a configuration example in order to use ECC ciphers with ACS 5.8. I noticed patch 4 support ECC for AAA flows, but i am looking for a guide and/or example in order to use it for EAP-TLS authentication.&lt;/P&gt;&lt;P&gt;thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin Rossignol&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 May 2017 20:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557763#M440694</guid>
      <dc:creator>berossig</dc:creator>
      <dc:date>2017-05-30T20:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and ECC ciphers</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557764#M440695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is to support certificates that supports ECC. This can work with EAP-FAST, PEAP-TLS and EAP-TLS client authentication.&lt;/P&gt;&lt;P&gt;Yes, you need the root/sub-ordinate CA to be in the trusted store for the user certificate to be validated like other certificate methods.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 00:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557764#M440695</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-05-31T00:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and ECC ciphers</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557765#M440696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please elaborate how to prepare the ACS please. I am the person who ask Ben the original question for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this was RSA - I would place the RSA ca certificate up in the "User and Identity Stores" location and then create a CSR in the System Administration &amp;gt; Local Server Certificate &amp;gt; Local Certificates location, sign and complete the request in the Outstanding&amp;nbsp; Signing Requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am using ECC - I would place the ECC ca certificate at the User and Identity Stores location and then generate a CSR but I noticed that the key length (512, 1024, 2048, 4096) and hash digest (SHA1, SHA256) don't match attributes of ECC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank-you,&lt;/P&gt;&lt;P&gt;Chris &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 01:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557765#M440696</guid>
      <dc:creator>chris-lawrence</dc:creator>
      <dc:date>2017-05-31T01:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and ECC ciphers</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557766#M440699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ECC certificates use ECDSA algorithm and not RSA as you might know.&lt;/P&gt;&lt;P&gt;Here is the comparison of key length between RSA and equivalent ECDSA&lt;/P&gt;&lt;P&gt;https://www.namecheap.com/support/knowledgebase/article.aspx/9503/38/what-is-an-ecc-elliptic-curve-cryptography-certificate&lt;/P&gt;&lt;P&gt;Here are few things you need to know when you are creating certificates for ACS&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-8/release/notes/acs_58_rn.html#pgfId-454084&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are instructions how to create a CSR using MS CA.&lt;/P&gt;&lt;P&gt;https://www.digicert.com/ecc-csr-creation-ssl-installation-microsoft.htm&lt;/P&gt;&lt;P&gt;and for apache&lt;/P&gt;&lt;P&gt;https://www.digicert.com/ecc-csr-creation-ssl-installation-apache.htm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additional information on ECC&lt;/P&gt;&lt;P&gt;https://www.digicert.com/ecc.htm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 22:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557766#M440699</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-05-31T22:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and ECC ciphers</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557767#M440701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this info...Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jun 2017 00:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-ecc-ciphers/m-p/3557767#M440701</guid>
      <dc:creator>chris-lawrence</dc:creator>
      <dc:date>2017-06-01T00:25:12Z</dc:date>
    </item>
  </channel>
</rss>

