<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate templates for EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424497#M509686</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, for LDAP.&amp;nbsp; For AD, it depends on how accounts are stored.&amp;nbsp; You could also set the FQDN or UPN in cert field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 May 2018 13:53:40 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-05-23T13:53:40Z</dc:date>
    <item>
      <title>Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424492#M509677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Are there recommended user and device certificate templates, the ones used in Windows CA for example. I have seen diffrent ways of doing it - diffrent values for SAN field for example. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason I ask is that I am wondering how the device group membership in AD is checked with EAP-TLS. I suppose it's one of the LDAP attributes?&amp;nbsp; I'd like to use device group membership in the authorisation rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rafal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 07:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424492#M509677</guid>
      <dc:creator>rkazmierczak</dc:creator>
      <dc:date>2018-05-23T07:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424493#M509679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically the Cert Auth Profile specifies the certificate field that contains the user id in AD.&amp;nbsp; Often this the Subject CN.&amp;nbsp; This value is then used to fetch group memberships like we would for any other type of Authorization.&amp;nbsp; Optionally you can assign values to specific cert fields like OU to have additional policy conditions such as IF OU=DivisionX, THEN ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specific to LDAP queries, the LDAP server definition defines the attribute in LDAP used to perform group membership lookups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 12:20:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424493#M509679</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-23T12:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424494#M509681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about the device certificate? what should I put in the subject name and what should I match for in the certificate profile? and finally how will the hostname be "extracted" so that a search in the AD can be done? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rafal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 12:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424494#M509681</guid>
      <dc:creator>rkazmierczak</dc:creator>
      <dc:date>2018-05-23T12:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424495#M509683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MAC address can be used.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 12:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424495#M509683</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-23T12:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424496#M509684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is it possible to do a search for AD group membership based on MAC address? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 13:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424496#M509684</guid>
      <dc:creator>rkazmierczak</dc:creator>
      <dc:date>2018-05-23T13:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424497#M509686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, for LDAP.&amp;nbsp; For AD, it depends on how accounts are stored.&amp;nbsp; You could also set the FQDN or UPN in cert field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 13:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424497#M509686</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-23T13:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate templates for EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424498#M509689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 14:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-templates-for-eap-tls/m-p/3424498#M509689</guid>
      <dc:creator>rkazmierczak</dc:creator>
      <dc:date>2018-05-23T14:39:38Z</dc:date>
    </item>
  </channel>
</rss>

