<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EAP Chaining with EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-eap-tls/m-p/3227219#M554321</link>
    <description>&lt;P&gt;Hello...re-deploying 802.1x within a network with high security requirements. Fully functional PKI deployment is already out that issues both user and machine certificates. Also using Cisco NAM 4.5 as supplicant and ISE 2.2 as RADIUS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting up EAP-TLS for machine authentication is very easy to do. User authentication not so much. When setting up the new profile in Network Access Manager and I get to the "Credentials" tab of the network setup, I am prompted to "Use Single Sign On Credentials" or "Prompt for Credentials". We do not use Smart Cards so I cannot use the SSO Creds but I want to provide my end uses with the SSO experience and not have them have to select a certificate to use for authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 668px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/4334iDAF9EC4A433A6FE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:40:53 GMT</pubDate>
    <dc:creator>Daryl Clark</dc:creator>
    <dc:date>2020-02-21T18:40:53Z</dc:date>
    <item>
      <title>EAP Chaining with EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-eap-tls/m-p/3227219#M554321</link>
      <description>&lt;P&gt;Hello...re-deploying 802.1x within a network with high security requirements. Fully functional PKI deployment is already out that issues both user and machine certificates. Also using Cisco NAM 4.5 as supplicant and ISE 2.2 as RADIUS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting up EAP-TLS for machine authentication is very easy to do. User authentication not so much. When setting up the new profile in Network Access Manager and I get to the "Credentials" tab of the network setup, I am prompted to "Use Single Sign On Credentials" or "Prompt for Credentials". We do not use Smart Cards so I cannot use the SSO Creds but I want to provide my end uses with the SSO experience and not have them have to select a certificate to use for authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 668px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/4334iDAF9EC4A433A6FE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-with-eap-tls/m-p/3227219#M554321</guid>
      <dc:creator>Daryl Clark</dc:creator>
      <dc:date>2020-02-21T18:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining with EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-eap-tls/m-p/3227347#M554322</link>
      <description>&lt;P&gt;Hi Daryl,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Under User Credentials select - Prompt for Credentials &amp;gt; Remember while user is logged on. Then under Certificate sources ensure "Smart card or OS certificates" is selected. I've used this configuration and machine/user authentication is transparent to the user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 19:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-with-eap-tls/m-p/3227347#M554322</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2017-12-05T19:13:46Z</dc:date>
    </item>
  </channel>
</rss>

