<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iPhone and Android connections via EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893901#M471298</link>
    <description>Point 1 : Apple Configurator 2 lets you configure an EAP-TLS profile with an identity certificate.&lt;BR /&gt;Point 2 : CA certificate is your server's certificate issuer's certificate and not the server certificate itself. If its a self signed certificate on the server then both are the same. For user certificate, one will have to choose a cert from existing identity certificates. This i believe is a one time thing for that SSID.</description>
    <pubDate>Fri, 19 Jul 2019 20:57:32 GMT</pubDate>
    <dc:creator>Surendra</dc:creator>
    <dc:date>2019-07-19T20:57:32Z</dc:date>
    <item>
      <title>iPhone and Android connections via EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893587#M471297</link>
      <description>&lt;P&gt;Thanks to the kind folks here, I've successfully configured ISE integration with my Cisco WLC to use EAP-TLS as an authentication method for iPhone and Anroid phones, but I have two problems I've yet to see an answer for in Apple and Google forums. Hoping someone has tried EAP-TLS with mobile phones here in prod:&lt;/P&gt;&lt;P&gt;1 - How do I get the client cert that is already installed on my iPhone to be a choice for 'identity' when I try signing on to the SSID? The cert came from the same CA as ISE and is in my Profile and Device Management store, but doesn't appear as a choice when I try signing on to that SSID upon hitting the controller.&lt;BR /&gt;2 - For the Android, I'm assuming the 'CA Certificate' means server-side certificate? For user certificate there's 'Please Select' but I think it's asking for manual input. What is needed here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody got any experience or links they can lend?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;ISE 2.4&lt;BR /&gt;Cisco 55xx WLC&lt;BR /&gt;iPhone IOS 12.3.1&lt;BR /&gt;Android Pixel 2 PQ Build&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 14:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893587#M471297</guid>
      <dc:creator>s1nsp4wn</dc:creator>
      <dc:date>2019-07-19T14:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: iPhone and Android connections via EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893901#M471298</link>
      <description>Point 1 : Apple Configurator 2 lets you configure an EAP-TLS profile with an identity certificate.&lt;BR /&gt;Point 2 : CA certificate is your server's certificate issuer's certificate and not the server certificate itself. If its a self signed certificate on the server then both are the same. For user certificate, one will have to choose a cert from existing identity certificates. This i believe is a one time thing for that SSID.</description>
      <pubDate>Fri, 19 Jul 2019 20:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893901#M471298</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-07-19T20:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: iPhone and Android connections via EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893904#M471299</link>
      <description>&lt;P&gt;I actually got somewhere on this earlier.&amp;nbsp; I already had what I needed trusted, but the problem was iPHone only accepts pfx or p12.&amp;nbsp; Once I changed format that issue was solved.&amp;nbsp; I still haven't gotten around to Android yet.&amp;nbsp; My current problem is that my client cert isn't accepted and is referred to as 'unsupported'.&amp;nbsp; &amp;nbsp;I did some digging around and found out that 'Key Usage' on the client cert must say either Client Authentication or have all usages enabled.&amp;nbsp; I'll ask my sysadmin to push a cert out to me from the same CA ISE uses to see if that works.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 21:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/3893904#M471299</guid>
      <dc:creator>s1nsp4wn</dc:creator>
      <dc:date>2019-07-19T21:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: iPhone and Android connections via EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/4023488#M471301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the certificate to be pushed on Android&amp;nbsp; the latter must request for it 1st. I wonder how u (or ur sysadmin) made it.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 16:18:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/iphone-and-android-connections-via-eap-tls/m-p/4023488#M471301</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2020-02-04T16:18:22Z</dc:date>
    </item>
  </channel>
</rss>

