<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-TLS with different root CA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528703#M538365</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ISE represents his Admin Certificate during the Provisioning. This will cause your Error on Windows Clients.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Jul 2016 06:28:56 GMT</pubDate>
    <dc:creator>Oliver Laue</dc:creator>
    <dc:date>2016-07-07T06:28:56Z</dc:date>
    <item>
      <title>EAP-TLS with different root CA</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528700#M538357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a customer who would like to deploy a different CA for EAP-TLS which is not part of the CA which signed the system certificates for ISE used for EAP. We will be importing this root CA in Trusted certificate store in ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would EAP-TLS be still successful (after throwing an unknown server warning ) if the endpoint is not trusting the server certificate ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone see such deployment in production ?&lt;/P&gt;&lt;P&gt;Basically the customer wants to EAP-TLS for BYOD devices but does not want to use internal CA for certificate provisioning due to security reasons.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jul 2016 11:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528700#M538357</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-07-04T11:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS with different root CA</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528701#M538361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE BYOD supports external SCEP and CA, such as MS AD CS. ISE BYOD will provision the root CA of ISE EAP server certificate along with the endpoint certificate so it should not be an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general case of the endpoint not trusting the EAP server certificate but requiring it validated, then EAP-TLS will fail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2016 05:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528701#M538361</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-07-05T05:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS with different root CA</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528702#M538364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested this scenario on Windows and Iphone 5. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows could not connect throwing an error of client rejecting server certificate on ISE however Iphone was prompted to trust ISE certificate before it authenticated successfully. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are not provisioning certificate out of band via an MDM so we will have to think of provisioning the ISE root CA as well. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2016 03:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528702#M538364</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-07-07T03:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS with different root CA</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528703#M538365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ISE represents his Admin Certificate during the Provisioning. This will cause your Error on Windows Clients.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2016 06:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-with-different-root-ca/m-p/3528703#M538365</guid>
      <dc:creator>Oliver Laue</dc:creator>
      <dc:date>2016-07-07T06:28:56Z</dc:date>
    </item>
  </channel>
</rss>

