<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-TLS with multiple domains? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3763686#M487352</link>
    <description>&lt;P&gt;Thank you very much &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;, it started to work after importing the CA cert. From security perspective, am&amp;nbsp;I supposed to do AD lookup too after the EAP-TLS machine/user cert check goes through?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whats the best practice?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am blanking at the moment, but what will happen if a user copies the certificate from their corporate laptop onto their personal laptop (assuming they have the smarts to use the same hostname as well)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Dec 2018 11:27:56 GMT</pubDate>
    <dc:creator>VS</dc:creator>
    <dc:date>2018-12-14T11:27:56Z</dc:date>
    <item>
      <title>EAP-TLS with multiple domains?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3760227#M487343</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have an ISE 2.2 p9 deployment. domain1.com AD joined to ISE and working well for our users. Another domain2.com is also connected to ISE as we use 2-way trust between domain1.com and domain2.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;domain1.com uses PEAP - this is our organization, we have the AD/CA certificates etc all configured and everything is fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But domain2.com is another organization, their laptops are set to use EAP-TLS. When they authenticate with our SSID we get error in ISE "12514 EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I understand I just need to download CA certificate from &lt;A href="http://domain2.com/certsrv" target="_blank"&gt;http://domain2.com/certsrv&lt;/A&gt; and import it in ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any additional step? Do I need to do the CSR process as well with their MS CA server?&lt;/P&gt;
&lt;P&gt;Will my ISE services restart?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Dec 2018 14:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3760227#M487343</guid>
      <dc:creator>VS</dc:creator>
      <dc:date>2018-12-09T14:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS with multiple domains?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3760244#M487346</link>
      <description>The only requirement is that your ISE server certificate needs to be trusted by the client and the client certificate needs to be trusted by ISE. &lt;BR /&gt;&lt;BR /&gt;Importing the domain2 CA cert should be fine as long as all those clients are issued a certificate from domain2.com. Your client seems to trust ISE server certificate given that ISE sends the server certificate first and then client responded by with it's certificate.&lt;BR /&gt;&lt;BR /&gt;ISE services will not restart if you just import a CA certificate.</description>
      <pubDate>Sun, 09 Dec 2018 15:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3760244#M487346</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-09T15:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS with multiple domains?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3763686#M487352</link>
      <description>&lt;P&gt;Thank you very much &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;, it started to work after importing the CA cert. From security perspective, am&amp;nbsp;I supposed to do AD lookup too after the EAP-TLS machine/user cert check goes through?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whats the best practice?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am blanking at the moment, but what will happen if a user copies the certificate from their corporate laptop onto their personal laptop (assuming they have the smarts to use the same hostname as well)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 11:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3763686#M487352</guid>
      <dc:creator>VS</dc:creator>
      <dc:date>2018-12-14T11:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS with multiple domains?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3763767#M487353</link>
      <description>&lt;P&gt;You can do an AD check from the information contained in the certificate, usually using the SAN field in the cert.&amp;nbsp; The hostname of the device doesn't matter.&amp;nbsp; If a user is able to export the certificate and private key (you need the private key to use a certificate to authenticate) from their corporate device they can use it to get any other device on the network.&amp;nbsp; Your certificate policies should mark the key as non-exportable.&amp;nbsp; Some OS types don't respect the do not export flag or if the user has knowledge there is way to get around the do not export flag.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 13:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-multiple-domains/m-p/3763767#M487353</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-12-14T13:50:31Z</dc:date>
    </item>
  </channel>
</rss>

