<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Client Certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896604#M471137</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;Technically, it seems to be a limitation in the endpoint side.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2019 11:44:26 GMT</pubDate>
    <dc:creator>fatalXerror</dc:creator>
    <dc:date>2019-07-24T11:44:26Z</dc:date>
    <item>
      <title>Multiple Client Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896554#M471131</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I have machine and user authentication using MAR in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have multiple certificates with the same CA-signed in my endpoint's certificate store (computer and user) and sometimes the endpoint uses a different certificate for the EAP authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I configure the endpoint to use a specific certificate for EAP authentication? I am using Windows 10 and ISE 2.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 10:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896554#M471131</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-07-24T10:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Client Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896570#M471134</link>
      <description>&lt;P&gt;Check this out : &lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj200227(v=ws.11)" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj200227(v=ws.11)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;For user certificates, Windows prompts the user to make a manual selection of which certificate to use. For computer certificates, the certificate with the highest weight is selected. If the selected certificate is the incorrect certificate for the connection, authentication fails. These filtering mechanisms are very rudimentary and user intervention is still required in most cases.&lt;BR /&gt;&lt;BR /&gt;This is interesting but not sure if it applies for machine authentication in Windows :&lt;BR /&gt;&lt;BR /&gt;Certificate weight as a filtering mechanism&lt;BR /&gt;When a Smart Card certificate is used for Pre-Logon-Access Provider (PLAP) scenarios, the weight of the certificate is also used for filtering. The weight of a certificate is determined by the certificate revocation list Distribution Point (CDP) and by the Authority Information Access (AIA) properties that are present in the certificate. AIA has a weight of 2 and CDP has a weight of 1. If both properties are present then Windows adds their weights together to determine the certificate weight. After this process, Windows selects and uses the certificate that has the highest weight value.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 02:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896570#M471134</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-25T02:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Client Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896578#M471135</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;I cannot open the link it says 404- Content Not Found.&lt;/P&gt;&lt;P&gt;Technically, Windows 10 cannot do it automatically? I mean without user intervention?&lt;/P&gt;&lt;P&gt;How about the Simple Certificate Selection (Advanced Setting), will it help?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 11:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896578#M471135</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-07-24T11:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Client Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896592#M471136</link>
      <description>I think in the URL there is ")" missing in the end when you click from this page. Anyways, SCS does not help specify a specific certificate to be used rather it simplifies the selection by showing only the relevant certificates to choose from and ordering those certificates smartly. It still involves user intervention.</description>
      <pubDate>Wed, 24 Jul 2019 11:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896592#M471136</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-24T11:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Client Certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896604#M471137</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;Technically, it seems to be a limitation in the endpoint side.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 11:44:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-client-certificates/m-p/3896604#M471137</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-07-24T11:44:26Z</dc:date>
    </item>
  </channel>
</rss>

