<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE CRL Distribution URL using LDAP Path in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4031299#M453868</link>
    <description>&lt;P&gt;Ages ago I looked into the logs to figure out how CRL works in ISE, and I noticed that by default, ISE looks into the CDP (CRL Distribution Point) and picks out the LDAP URL and tries to bind to it. It fails of course because there is no setup for this option. I don't know if this is still the case in ISE 2.6.&amp;nbsp; The manual option is to specify a http URL and I don't see any options to bind to an LDAP repository.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2020 02:11:09 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2020-02-18T02:11:09Z</dc:date>
    <item>
      <title>ISE CRL Distribution URL using LDAP Path</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4031047#M453867</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if ISE supports CRL checking from an LDAP path as opposed to a http path? I have looked through the documentation and I cant see this mentioned anywhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 16:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4031047#M453867</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2020-02-17T16:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CRL Distribution URL using LDAP Path</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4031299#M453868</link>
      <description>&lt;P&gt;Ages ago I looked into the logs to figure out how CRL works in ISE, and I noticed that by default, ISE looks into the CDP (CRL Distribution Point) and picks out the LDAP URL and tries to bind to it. It fails of course because there is no setup for this option. I don't know if this is still the case in ISE 2.6.&amp;nbsp; The manual option is to specify a http URL and I don't see any options to bind to an LDAP repository.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 02:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4031299#M453868</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-18T02:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CRL Distribution URL using LDAP Path</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4033926#M558227</link>
      <description>&lt;P&gt;ISE validates CRLs for two purposes and each done its own way.&lt;/P&gt;
&lt;P&gt;1. A CRL configured with a trusted root CA. This is to validate the end-entity certificates issued by this CA chain for EAP-TLS or other cert-based authentications, etc. For this, only the configured CRL is checked and the URL can be of LDAP but only anonymous binding works.&lt;/P&gt;
&lt;P&gt;2. Auto-validation of ISE server certificates used for inter-ISE-node communications. For this, ISE extracts the CRL distribution Point (CDP) from the server certificates and attempts to validate. Again, only anonymous binding works, if using LDAP URL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 21:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-crl-distribution-url-using-ldap-path/m-p/4033926#M558227</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-02-21T21:43:05Z</dc:date>
    </item>
  </channel>
</rss>

