<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Authentication Profile (CAP) - Identity Store Query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576653#M527329</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Aug 2017 01:43:14 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-08-30T01:43:14Z</dc:date>
    <item>
      <title>Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576646#M527314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Members,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we have Certificate Authentication Profile setup and haven't setup Identity Sequence in Authentication Profile, which Identity Store would ISE look for attributes mentioned in CAP Policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Aug 2017 03:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576646#M527314</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-08-27T03:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576647#M527316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The certificate attribute designated for the user identity is used as the subject/user to lookup for groups/attributes in identity stores as specified in the authorization policy rules. They can be any internal or external identity stores configured in ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Aug 2017 02:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576647#M527316</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-28T02:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576648#M527317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about the authentication part?&lt;/P&gt;&lt;P&gt;For Authentication, would it check the ID Store specified in Authorization rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576648#M527317</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-08-30T01:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576649#M527320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on Steps 3 ~ 5 of &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01110.html#task_CBFBF2B60E014B8E8B74D271DC047E47" style="font-size: 10pt;"&gt;Add a Certificate Authentication Profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In case that no identity store chosen in Step 3, then ISE uses those certificates designed for client authentication in Trusted Certificates only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576649#M527320</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-30T01:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576650#M527321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks hslai.&lt;/P&gt;&lt;P&gt;Could you please have a look at the attached CAP Profile?&lt;/P&gt;&lt;P&gt;Would it be checking ID Store specified in Authorization Rule?&lt;/P&gt;&lt;P&gt;If yes, what happens during Authentication? How would the user get authenticated?&lt;IMG alt="CAP Profile.JPG" class="image-1 jive-image" src="/legacyfs/online/fusion/110856_CAP Profile.JPG" style="height: 269px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576650#M527321</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-08-30T01:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576651#M527323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "Identity Store" is set to [not applicable] so the authentications will be based on trusted certs only. ISE will still perform groups/attributes lookup using the subject alternative name as user name if your authorization policy rules are using those identity stores.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576651#M527323</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-30T01:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576652#M527325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks hslai, that makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if I'm wrong:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication Part: If user certificate is from trusted CA, the user gets authenticated and no ID Stores would be checked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization Part: Subject Alternative Name would be checked in the ID stores as per Authorization Policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576652#M527325</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-08-30T01:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576653#M527329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576653#M527329</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-30T01:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576654#M527332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any basic config example for certificate based authentication both for ISE and Client side?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576654#M527332</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-08-30T01:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576655#M527334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="5301" data-containertype="14" data-objectid="63882" data-objecttype="102" href="https://community.cisco.com/docs/DOC-63882"&gt;ISE Training&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; has links to various materials.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;We have some GOLD labs via SalesConnect but these offerings are ending this Thursday.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;BYOD -- shows using ISE BYOD to provision a certificate to an Apple iDevice using ISE internal CA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Integrating ISE with Active Directory -- shows using GPO in AD to provision certificates and authorize using AD.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 02:17:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576655#M527334</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-30T02:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Authentication Profile (CAP) - Identity Store Query</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576656#M527335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks hslai for your comments and suggestions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 03:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-authentication-profile-cap-identity-store-query/m-p/3576656#M527335</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-08-30T03:12:35Z</dc:date>
    </item>
  </channel>
</rss>

