<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: With EAP-TLS authentication does the client certificate need to be in Trusted Cert store? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579618#M520224</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I answered my first question earlier today about client cert in Trusted store…..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In response to your question – I would use the internal ISE certificate authority if I could. Unfortunately our devices (using a TI chipset) do not support 4096-bit keys, and the internal ISE root cert used has a 4096-bit key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may not need to use a BYOD ‘spoof’ though since the client certificates do not need to be in the Trusted Cert store……our customer requirement currently is to use an external trusted root CA, which is why I am using a 2012 R2 server……I have options for authenticating ‘smarter’ devices and users that way as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will look more at the provisioning portal as well as BYOD for other clients….thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karl Peters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;858-201-8840&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Nov 2017 18:11:05 GMT</pubDate>
    <dc:creator>kpeters011</dc:creator>
    <dc:date>2017-11-02T18:11:05Z</dc:date>
    <item>
      <title>With EAP-TLS authentication does the client certificate need to be in Trusted Cert store?</title>
      <link>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579616#M520222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm setting up my ISE (ver 2.3.0.298) to do EAP-TLS authentication with various wireless devices. The devices are not capable of using SCEP to obtain their certificates and keys, so I am going to have to setup a laptop to request access through the ISE and have the ISE communicate to my external SCEP proxy (Microsoft Server 2012 R2) to request client certificates......&lt;/P&gt;&lt;P&gt;My first question is this - do all the client certificates (we may have up to 100,000 of these devices) need to be loaded into the Trusted Certificate store on the ISE (I believe they would need to for EAP-TLS to function)??&lt;/P&gt;&lt;P&gt;If they do need to be in the Trusted Certificate store for client certificate validation can I use a BYOD device to get certificates through the ISE BYOD portal communicating to my Microsoft MSCEP service and will the retrieved client certificates be automatically placed into the ISE Trusted Certificate store??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 17:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579616#M520222</guid>
      <dc:creator>kpeters011</dc:creator>
      <dc:date>2017-11-02T17:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: With EAP-TLS authentication does the client certificate need to be in Trusted Cert store?</title>
      <link>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579617#M520223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No the certificates of each client  do not need to be in the trusted certificate store&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to put the root certificate chain of your PKI server into the trusted certificate store in order to trust the endpoint clients for authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a reason you’re not using the internal certificate authority on ise itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have the certificate provisioning portal to help with onboarding of IOT devices and this can be access via an API, please reference the admin guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For byod and understanding of integration please look at http://cs.co/ise-community under byod for examples on how to integrate with external server if needed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 17:45:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579617#M520223</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-02T17:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: With EAP-TLS authentication does the client certificate need to be in Trusted Cert store?</title>
      <link>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579618#M520224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I answered my first question earlier today about client cert in Trusted store…..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In response to your question – I would use the internal ISE certificate authority if I could. Unfortunately our devices (using a TI chipset) do not support 4096-bit keys, and the internal ISE root cert used has a 4096-bit key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may not need to use a BYOD ‘spoof’ though since the client certificates do not need to be in the Trusted Cert store……our customer requirement currently is to use an external trusted root CA, which is why I am using a 2012 R2 server……I have options for authenticating ‘smarter’ devices and users that way as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will look more at the provisioning portal as well as BYOD for other clients….thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karl Peters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;858-201-8840&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 18:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579618#M520224</guid>
      <dc:creator>kpeters011</dc:creator>
      <dc:date>2017-11-02T18:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: With EAP-TLS authentication does the client certificate need to be in Trusted Cert store?</title>
      <link>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579619#M520225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks! It sounds like you’re allset&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 18:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/with-eap-tls-authentication-does-the-client-certificate-need-to/m-p/3579619#M520225</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-02T18:24:53Z</dc:date>
    </item>
  </channel>
</rss>

