<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: certificate usage for client authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458719#M538050</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the trust option [ trust for client authentication and syslog ] is a pre-requisit for the root CA certificate used for EAP-TLS client authentications.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Aug 2016 20:46:01 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2016-08-04T20:46:01Z</dc:date>
    <item>
      <title>certificate usage for client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458716#M538042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Environment will have a publicly signed certificate installed on ISE as system certificate for EAP and portal use.&amp;nbsp; In addition ISE is authenticating client devices via EAP-TLS using certificates signed by private a CA on company network.&amp;nbsp; Need to make sure that only certificates signed by the internal CA are authenticated and not any certificates signed by the same public CA.&amp;nbsp; Is it only trusted certificates that have Usage: "trust for client authetication and syslog" that are used for EAP-TLS client authentication?&amp;nbsp; Need to make sure that the system certificate used for EAP and other trusted certificates are not used by ISE for client certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Aug 2016 21:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458716#M538042</guid>
      <dc:creator>greg2.0</dc:creator>
      <dc:date>2016-08-03T21:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: certificate usage for client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458717#M538045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have come across this kind of scenario before where we made use of a differentiating parameter (SAN) in the certificate template and referred the condition in authorization policies. &lt;/P&gt;&lt;P&gt;In your case if a client comes with a certificate signed by the public CA it should also match the condition for the parameter in the authorization profile. Since you own the internal CA you can come with a unique identifier and prevent clients presenting certificates signed by public CAs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2016 09:23:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458717#M538045</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-08-04T09:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: certificate usage for client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458718#M538048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Utkarsh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess my question is are authorization policies necessary in this case?&amp;nbsp; Will the Usage: "trust for client authetication and syslog" setting on the trusted certificate limit EAP-TLS authentication to only certificates signed by that trusted root?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2016 17:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458718#M538048</guid>
      <dc:creator>greg2.0</dc:creator>
      <dc:date>2016-08-04T17:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: certificate usage for client authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458719#M538050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the trust option [ trust for client authentication and syslog ] is a pre-requisit for the root CA certificate used for EAP-TLS client authentications.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2016 20:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-usage-for-client-authentication/m-p/3458719#M538050</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-04T20:46:01Z</dc:date>
    </item>
  </channel>
</rss>

