<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does ISE REST API encrypt data to and from the ISE server? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439137#M519483</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I read that as well. It says they are encrypted but does not give details on HOW it is encrypted. That is a big deal for customers with IA audits. They need to know if it's a one way hash, uses a shared encryption key, uses the servers public asymmetrical key or just passed inside an encrypted TLS connection i.e. not encrypted. I could not find any docs internally that clarifies those details. And someone else is now saying it is not encrypted.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Nov 2017 16:01:15 GMT</pubDate>
    <dc:creator>Tim Baum</dc:creator>
    <dc:date>2017-11-29T16:01:15Z</dc:date>
    <item>
      <title>How does ISE REST API encrypt data to and from the ISE server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439134#M519476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've read that ISE REST API uses TLS (https) over port 9060 with basic authentication. Is there any additional encryption being done for the username and/or password other than sending the data thru the TLS tunnel? e.g. password encrypted with public key of ISE server or some hash?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 21:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439134#M519476</guid>
      <dc:creator>Tim Baum</dc:creator>
      <dc:date>2017-11-28T21:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: How does ISE REST API encrypt data to and from the ISE server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439135#M519478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P class="pB1_Body1" style="margin-top: 12px; margin-bottom: 12px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;The External RESTful Services APIs are based on HTTPS protocol and REST methodology and uses port 9060.&lt;/P&gt;
&lt;P class="pB1_Body1" style="margin-top: 12px; margin-bottom: 12px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;&lt;A name="pgfId-1092472" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;The External RESTful Services APIs support basic authentication. The authentication credentials are encrypted and are part of the request header.&lt;/P&gt;
&lt;P class="pB1_Body1" style="margin-top: 12px; margin-bottom: 12px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;&lt;A name="pgfId-1092473" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;The ISE administrator must assign special privileges to a user to perform operations using the External RESTful Services APIs.&lt;/P&gt;
&lt;P class="pB1_Body1" style="margin-top: 12px; margin-bottom: 12px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;&lt;A name="pgfId-1092474" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;To perform operations using the External RESTful Services APIs (except for the Guest API), the users must be assigned to one of the following Admin Groups and must be authenticated against the credentials stored in the Cisco ISE internal database (internal admin users):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A name="pgfId-1092475" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;External RESTful Services Admin—Full access to all ERS APIs (GET, POST, DELETE, PUT). This user can Create, Read, Update, and Delete ERS API requests.&lt;/LI&gt;
&lt;LI&gt;&lt;A name="pgfId-1092476" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;External RESTful Services Operator—Read Only access (GET request only).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="pB1_Body1" style="margin-top: 12px; margin-bottom: 12px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;&lt;A name="pgfId-1092477" style="font-style: inherit; font-size: inherit; font-family: inherit; color: #007fab;"&gt;&lt;/A&gt;If you do not have the required permissions and still try to perform operations using the External RESTful Services APIs, you will receive an error response.&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;According to the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/api_ref_guide/api_ref_book/ise_api_ref_ers1.html#pgfId-1079726"&gt;Cisco Identity Services Engine API Reference Guide, Release 2.x&lt;/A&gt;, the authentication credentials ARE encrypted and not just sent through the tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 21:25:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439135#M519478</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-11-28T21:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: How does ISE REST API encrypt data to and from the ISE server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439136#M519481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. It’s no different than logging into your bank’s web site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Warning: I either dictated this to my device, or typed it with my thumbs. Erroneous words are a feature, not a typo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 21:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439136#M519481</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-11-28T21:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: How does ISE REST API encrypt data to and from the ISE server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439137#M519483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I read that as well. It says they are encrypted but does not give details on HOW it is encrypted. That is a big deal for customers with IA audits. They need to know if it's a one way hash, uses a shared encryption key, uses the servers public asymmetrical key or just passed inside an encrypted TLS connection i.e. not encrypted. I could not find any docs internally that clarifies those details. And someone else is now saying it is not encrypted.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 16:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-ise-rest-api-encrypt-data-to-and-from-the-ise-server/m-p/3439137#M519483</guid>
      <dc:creator>Tim Baum</dc:creator>
      <dc:date>2017-11-29T16:01:15Z</dc:date>
    </item>
  </channel>
</rss>

