<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why we do not support this Authentication protocol (EAP-MSCHAP) with External identity source like LDAP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501656#M496898</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I have a public sector customer with external LDAP as user database, and they are using right now a ClearPass as radius Server. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;This kind of customers are from Education Sector, where the pc &amp;amp; notebook are old, and in many cases don’t have support or aren´t&amp;nbsp;&amp;nbsp; managed centrally., so installing a client or certificate is not an option.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;The authentication protocol is EAP-MSCHAPv1/v2 with LDAP as external identity source is the only choice for them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;Today everything is working fine for them, but in the migration process from ClearPass to ISE, the problem is the lack of support of this combination (EAP-MSCHAP with LDAP ( Oracle or OpenLdap ) as external database.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;Now the workaround is using the ISE as proxy radius of ClearPAss, but this is not a satisfactory solution for the customer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;This issue is not only for this specific customer, as we will have the same problem in almost all Public Sector customers if we want to go with ISE as solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I have a specific question regarding why we do not support this Authentication protocol with External identity source like:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;MSCHAPv1/v2&amp;nbsp; with LDAP (LDAP as Ext.Identity Source)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; or&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;EAP-MSCHAPv2 with LDAP (LDAP as Ext.Identy Source)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I need to answer with technical detail information about why we don´t support it but ClearPass does. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I Repeat it is not an option&amp;nbsp; using&amp;nbsp;&amp;nbsp; the ISE as proxy radius of ClearPass.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I have not&amp;nbsp; found any document with a detailed answer&amp;nbsp; to explain to&amp;nbsp; my customer why it does not&amp;nbsp; work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I need you help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jun 2018 21:23:16 GMT</pubDate>
    <dc:creator>lemontan</dc:creator>
    <dc:date>2018-06-18T21:23:16Z</dc:date>
    <item>
      <title>Why we do not support this Authentication protocol (EAP-MSCHAP) with External identity source like LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501656#M496898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I have a public sector customer with external LDAP as user database, and they are using right now a ClearPass as radius Server. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;This kind of customers are from Education Sector, where the pc &amp;amp; notebook are old, and in many cases don’t have support or aren´t&amp;nbsp;&amp;nbsp; managed centrally., so installing a client or certificate is not an option.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;The authentication protocol is EAP-MSCHAPv1/v2 with LDAP as external identity source is the only choice for them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;Today everything is working fine for them, but in the migration process from ClearPass to ISE, the problem is the lack of support of this combination (EAP-MSCHAP with LDAP ( Oracle or OpenLdap ) as external database.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;Now the workaround is using the ISE as proxy radius of ClearPAss, but this is not a satisfactory solution for the customer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;This issue is not only for this specific customer, as we will have the same problem in almost all Public Sector customers if we want to go with ISE as solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I have a specific question regarding why we do not support this Authentication protocol with External identity source like:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;MSCHAPv1/v2&amp;nbsp; with LDAP (LDAP as Ext.Identity Source)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; or&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;EAP-MSCHAPv2 with LDAP (LDAP as Ext.Identy Source)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I need to answer with technical detail information about why we don´t support it but ClearPass does. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I Repeat it is not an option&amp;nbsp; using&amp;nbsp;&amp;nbsp; the ISE as proxy radius of ClearPass.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I have not&amp;nbsp; found any document with a detailed answer&amp;nbsp; to explain to&amp;nbsp; my customer why it does not&amp;nbsp; work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;I need you help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 21:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501656#M496898</guid>
      <dc:creator>lemontan</dc:creator>
      <dc:date>2018-06-18T21:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why we do not support this Authentication protocol (EAP-MSCHAP) with External identity source like LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501657#M496901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mainly due to planning and priority. Please discuss it with our PM team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 21:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501657#M496901</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-18T21:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why we do not support this Authentication protocol (EAP-MSCHAP) with External identity source like LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501658#M496902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add a bit more color, to make the MSCHAP password accessible available to LDAP requires that you reduce password security by storing the password in cleartext and regenerate hash for use in auth exchange, or store in a reversibly encrypted LDAP store.&amp;nbsp; Still, customers have expressed a desire to implement such functionality even if not as secure as AD password storage, so feature has been raised in priority.&amp;nbsp; Use of Secure LDAP may reduce some of the security concerns.&amp;nbsp; In any case, the original decision not to include LDAP support for PEAP-EAP-MSCHAPv2 was based on security concerns that another vendor may never even mention to their customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 12:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-we-do-not-support-this-authentication-protocol-eap-mschap/m-p/3501658#M496902</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-19T12:31:22Z</dc:date>
    </item>
  </channel>
</rss>

