<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic different certs used for eap on endpoint attached to switch port in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/different-certs-used-for-eap-on-endpoint-attached-to-switch-port/m-p/3759704#M487395</link>
    <description>&lt;P&gt;Forwarding question: Currently the workstations have been configured are all working fine with a legacy SHA1 certificate and PEAP-TLS but the Avaya ip phones do not authenticate with the error “12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate”.&lt;BR /&gt;&lt;BR /&gt;One issue is that the phones currently use a SHA256 certificate for EAP-TLS and the workstations use SHA1. We are due to upgrade to SHA256 for the workstations in the coming months but have an issue with compatibility as currently a 4.2 ACS server which is currently in place does not work on 2008R2 potentially breaking our radius authentications.&lt;BR /&gt;&lt;BR /&gt;So the plan was to replace ACS with ISE and then upgrade the certificate server when we hit the current issue. Is it possible to have 2 different EAP-TLS authentication certificates? I did attempt this but when I go to bind the cert ISE states that this will override the current binding. Otherwise is there a temporary solution to MAB the ip phones and dot1x the workstations?&lt;/P&gt;</description>
    <pubDate>Fri, 07 Dec 2018 17:15:24 GMT</pubDate>
    <dc:creator>mpeeters</dc:creator>
    <dc:date>2018-12-07T17:15:24Z</dc:date>
    <item>
      <title>different certs used for eap on endpoint attached to switch port</title>
      <link>https://community.cisco.com/t5/network-access-control/different-certs-used-for-eap-on-endpoint-attached-to-switch-port/m-p/3759704#M487395</link>
      <description>&lt;P&gt;Forwarding question: Currently the workstations have been configured are all working fine with a legacy SHA1 certificate and PEAP-TLS but the Avaya ip phones do not authenticate with the error “12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate”.&lt;BR /&gt;&lt;BR /&gt;One issue is that the phones currently use a SHA256 certificate for EAP-TLS and the workstations use SHA1. We are due to upgrade to SHA256 for the workstations in the coming months but have an issue with compatibility as currently a 4.2 ACS server which is currently in place does not work on 2008R2 potentially breaking our radius authentications.&lt;BR /&gt;&lt;BR /&gt;So the plan was to replace ACS with ISE and then upgrade the certificate server when we hit the current issue. Is it possible to have 2 different EAP-TLS authentication certificates? I did attempt this but when I go to bind the cert ISE states that this will override the current binding. Otherwise is there a temporary solution to MAB the ip phones and dot1x the workstations?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 17:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/different-certs-used-for-eap-on-endpoint-attached-to-switch-port/m-p/3759704#M487395</guid>
      <dc:creator>mpeeters</dc:creator>
      <dc:date>2018-12-07T17:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: different certs used for eap on endpoint attached to switch port</title>
      <link>https://community.cisco.com/t5/network-access-control/different-certs-used-for-eap-on-endpoint-attached-to-switch-port/m-p/3759766#M487397</link>
      <description>You cannot have two different certificates for EAP on a single ISE server.&lt;BR /&gt;&lt;BR /&gt;You can check with Avaya support if there is a way to stop the phones from talking EAP (doing dot1x). If they can, then yes, you can have the phones do MAB and the PCs will continue to do dot1x.</description>
      <pubDate>Fri, 07 Dec 2018 19:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/different-certs-used-for-eap-on-endpoint-attached-to-switch-port/m-p/3759766#M487397</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-07T19:22:05Z</dc:date>
    </item>
  </channel>
</rss>

