<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3230652#M550969</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I want to be able to enable or disable specific ciphers or TLS versions for a specific authentication protocol definition&lt;BR /&gt; Policy -&amp;gt; Policy elements&amp;nbsp;-&amp;gt; Authentication -&amp;gt; Allowed protocols&lt;/P&gt;
&lt;P&gt;Currently all I can do is enable or disable weak ciphers (see attached picture), or enable or disable TLS1.0/TLS1.1 installation-wide (Admin -&amp;gt; System -&amp;gt; Settings -&amp;gt; Protocols -&amp;gt; Security settings).&lt;/P&gt;
&lt;P&gt;Are there any plans for doing this in the future ?&lt;/P&gt;
&lt;P&gt;If not, then please add options to enable or disable these already-existing settings to the auth protocol definition settings.&lt;/P&gt;
&lt;P&gt;For cipher suite selections,&amp;nbsp;I don't need a fancy&amp;nbsp;cipher suite selection UI - a simple string field for cipher suites (as input to OpenSSL) would be fine. But a simple "enable weak ciphers" is&amp;nbsp;not good enough, if I for some reason need to disable a specific cipher set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards Henrik&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:41:14 GMT</pubDate>
    <dc:creator>henrikj</dc:creator>
    <dc:date>2020-02-21T18:41:14Z</dc:date>
    <item>
      <title>Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules</title>
      <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3230652#M550969</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I want to be able to enable or disable specific ciphers or TLS versions for a specific authentication protocol definition&lt;BR /&gt; Policy -&amp;gt; Policy elements&amp;nbsp;-&amp;gt; Authentication -&amp;gt; Allowed protocols&lt;/P&gt;
&lt;P&gt;Currently all I can do is enable or disable weak ciphers (see attached picture), or enable or disable TLS1.0/TLS1.1 installation-wide (Admin -&amp;gt; System -&amp;gt; Settings -&amp;gt; Protocols -&amp;gt; Security settings).&lt;/P&gt;
&lt;P&gt;Are there any plans for doing this in the future ?&lt;/P&gt;
&lt;P&gt;If not, then please add options to enable or disable these already-existing settings to the auth protocol definition settings.&lt;/P&gt;
&lt;P&gt;For cipher suite selections,&amp;nbsp;I don't need a fancy&amp;nbsp;cipher suite selection UI - a simple string field for cipher suites (as input to OpenSSL) would be fine. But a simple "enable weak ciphers" is&amp;nbsp;not good enough, if I for some reason need to disable a specific cipher set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards Henrik&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3230652#M550969</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2020-02-21T18:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules</title>
      <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3297159#M550974</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Henrik,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My name is Tal Surasky and I'm one of ISE's product manager.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Currently changing protocols settings is something we can do in a deployment-wide settings only and not as you requested, per policy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you please elaborate&amp;nbsp;on the use case and why do you need this option?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tal&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2017 08:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3297159#M550974</guid>
      <dc:creator>surasky</dc:creator>
      <dc:date>2017-12-16T08:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules</title>
      <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3304787#M551039</link>
      <description>&lt;P&gt;The use cases for changing TLS cipher/protocol settings per policy, and not deployment-wide, are the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enabling enterprise clients to use more strict cryptographic settings, than BYOD/non-enterprise devices&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Deprecating weak ciphers faster&lt;/LI&gt;
&lt;LI&gt;Only using the newest protocol versions&lt;/LI&gt;
&lt;LI&gt;Synchronized security policy with Group Policies for Windows clients, etc.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Possibility to act fast on enterprise clients and change cipher and protocol settings with a better granularity, based on risk assessment and vulnerability reports etc.&lt;/LI&gt;
&lt;LI&gt;Possibility to differentiate clients based on cryptographic settings&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Placing clients without updated GPO with missing settings in a “high-risk” network or in network for remediation / GPO update, opposed to dealing with disconnected clients after security settings have been strengthened&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Might even want to use very weak ciphers for special devices (printers, phones, etc) instead of MAB – as security is still higher. But do NOT want to use weak crypto settings on enterprise devices. Need to have separate policies for the two.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Eg. Use EAP-PEAP-MD5 or similar as replacement for MAB, for devices that support EAP – but will most certainly have devices that only support older protocol versions and weaker ciphers&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 14:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3304787#M551039</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2018-01-02T14:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules</title>
      <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3841010#M551040</link>
      <description>&lt;P&gt;Hi&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt; henrikj&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Did you get a response on this? l need to do the same too.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Vusa&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 10:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3841010#M551040</guid>
      <dc:creator>vusandlovu</dc:creator>
      <dc:date>2019-04-18T10:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules</title>
      <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3848450#M551041</link>
      <description>&lt;P&gt;No &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 10:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3848450#M551041</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2019-05-01T10:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sellect different ciphers in ISE 2.3 and forward for EAP-TLS for different rules</title>
      <link>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3854495#M551042</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;How to Ask The Community for Help&lt;/A&gt;&amp;nbsp;outlines,&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="#toc-hId-519934988" rel="nofollow noopener noreferrer" target="_blank"&gt;No Comment on Roadmaps or Fixes&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#toc-hId--1287519475" rel="nofollow noopener noreferrer" target="_blank"&gt;New Features and Feedback&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 00:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sellect-different-ciphers-in-ise-2-3-and-forward-for-eap-tls-for/m-p/3854495#M551042</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-05-12T00:11:48Z</dc:date>
    </item>
  </channel>
</rss>

