<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TEAP and Macs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4734761#M578719</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was playing with MacOS EAP-TLS authentication and tried to solve machine authentication. I was able to authenticate with machine cert of the MacOS but... regardless of location of the machine cert (login / system key chain) I saw from the Cisco ISE logs that the authentication was always&amp;nbsp;&lt;STRONG&gt;IsMachineIdentity false&lt;/STRONG&gt; so I had to do a trick. Generated a machine cert with SAN &lt;STRONG&gt;host/&lt;/STRONG&gt;HOSTNAME.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;When the host/ prefix was included in the SAN the ISE started to authenticate with parameter&amp;nbsp;&lt;STRONG&gt;IsMachineIdentity true&lt;/STRONG&gt;. Just then it started to search for a computers in AD.&lt;/P&gt;&lt;P&gt;But still. When I tried to do a similar tests like on Windows platform I was not successful. A very basic test. When I turned on the MacOS and I saw the prompt to login to the system I still was not authenticated by machine cert. So the MacOS was not assigned to vlan and did not have an IP address. When I entered the login credentials just then MacOS reached the keychain and authenticated to network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within Windows platform, when you are asked to login, the Windows is already ready to use machine cert to authenticate based on machine identity. And then when you enter your credentials the user auth is in place. With TEAP, combined as one authentication machine+user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought that login/system key chain (in MacOS world) is equivalent of user/computer (Windows world) cert store. But this is not so true or maybe I just do not understand the concept. I have went through a lot of articles regarding this MacOS user/computer auth and EAP chaining topic and it caused me a serious head aches. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So I am not sure if there is such a concept like computer authentication in the MacOS world.&lt;/P&gt;&lt;P&gt;If anybody knows how it works I would be glad for any info, just for my curiosity.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2022 10:37:57 GMT</pubDate>
    <dc:creator>Barney</dc:creator>
    <dc:date>2022-12-08T10:37:57Z</dc:date>
    <item>
      <title>TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4586790#M573900</link>
      <description>&lt;P&gt;Has their been any progress/update on the possibility of OS X supporting TEAP (RFC 7170)?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 21:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4586790#M573900</guid>
      <dc:creator>fitzie</dc:creator>
      <dc:date>2022-04-05T21:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4586798#M573901</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/345407"&gt;@fitzie&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently there is no need for this feature on Apple MACOS. As far as I am aware, there is no distinction between Computer and User authentication on MACOS. In the Windows world there is - and that is why EAP Chaining is such a big deal.&lt;/P&gt;
&lt;P&gt;The MACOS supplicants can be configured with other Methods like EAP-TLS, EAP-PEAP, EAP-TTLS and any RADIUS server can handle them as "business as usual".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 22:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4586798#M573901</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-04-05T22:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4602081#M574422</link>
      <description>&lt;P&gt;I don't necessarily agree with your statement that there is no need for this feature in OS X, as I want to be able to use both the machine identity and the user identity for different aspects of NAC.&amp;nbsp; Haing a singular approach in an environment where both Macs and WIndows machines exist as end-user devices is preferable to having two disparate methods which don't behave in the same way.&amp;nbsp; Without going into the details/reauirements of my environment,&amp;nbsp; can easily state that my Mac users have a much harder time with it than my Windows users.&amp;nbsp; Not all business is usual.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 21:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4602081#M574422</guid>
      <dc:creator>fitzie</dc:creator>
      <dc:date>2022-04-28T21:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4602148#M574423</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/345407"&gt;@fitzie&lt;/a&gt;&amp;nbsp;- I agree that it would be nice to "&lt;SPAN&gt;&amp;nbsp;... be able to use both the machine identity and the user identity for different aspects of NAC." - but my point was that as far as I know, MACOS does not have that concept - Windows desktop operating systems were designed to be used in enterprise environments with the clear distinction between computer and user auth as part of the Active Directory domain concept. Do you know for a fact that MACOS has this ability as well? i.e. have you seen the supplicant perform differentiated authentication depending on whether the user is logged in or logged out?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 22:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4602148#M574423</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-04-28T22:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4734761#M578719</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was playing with MacOS EAP-TLS authentication and tried to solve machine authentication. I was able to authenticate with machine cert of the MacOS but... regardless of location of the machine cert (login / system key chain) I saw from the Cisco ISE logs that the authentication was always&amp;nbsp;&lt;STRONG&gt;IsMachineIdentity false&lt;/STRONG&gt; so I had to do a trick. Generated a machine cert with SAN &lt;STRONG&gt;host/&lt;/STRONG&gt;HOSTNAME.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;When the host/ prefix was included in the SAN the ISE started to authenticate with parameter&amp;nbsp;&lt;STRONG&gt;IsMachineIdentity true&lt;/STRONG&gt;. Just then it started to search for a computers in AD.&lt;/P&gt;&lt;P&gt;But still. When I tried to do a similar tests like on Windows platform I was not successful. A very basic test. When I turned on the MacOS and I saw the prompt to login to the system I still was not authenticated by machine cert. So the MacOS was not assigned to vlan and did not have an IP address. When I entered the login credentials just then MacOS reached the keychain and authenticated to network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within Windows platform, when you are asked to login, the Windows is already ready to use machine cert to authenticate based on machine identity. And then when you enter your credentials the user auth is in place. With TEAP, combined as one authentication machine+user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought that login/system key chain (in MacOS world) is equivalent of user/computer (Windows world) cert store. But this is not so true or maybe I just do not understand the concept. I have went through a lot of articles regarding this MacOS user/computer auth and EAP chaining topic and it caused me a serious head aches. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So I am not sure if there is such a concept like computer authentication in the MacOS world.&lt;/P&gt;&lt;P&gt;If anybody knows how it works I would be glad for any info, just for my curiosity.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 10:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4734761#M578719</guid>
      <dc:creator>Barney</dc:creator>
      <dc:date>2022-12-08T10:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4734882#M578722</link>
      <description>&lt;P&gt;There is no concept of a "machine account" in MacOS.&amp;nbsp; There are a "system" and "user" certificate keychains but this is not the same as the Windows machine account concept.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 13:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4734882#M578722</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-12-08T13:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP and Macs</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4740015#M578855</link>
      <description>&lt;P&gt;I am not aware of any plans for Apple to support the TEAP protocol on &lt;EM&gt;any&lt;/EM&gt; of their platforms.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 00:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-and-macs/m-p/4740015#M578855</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-12-16T00:09:53Z</dc:date>
    </item>
  </channel>
</rss>

