<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-TLS Computer Authetication Failing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-computer-authetication-failing/m-p/4861510#M582435</link>
    <description>&lt;P&gt;If the machine name is populated in the SAN then I think you can change the certificate attribute in the certificate authentication policy (CAP) in ISE to lookup for the SAN rather than the CN value. To change that click on the drop down menu and select Subject Alternative Name - DNS or Other Name.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2023 15:51:13 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2023-06-23T15:51:13Z</dc:date>
    <item>
      <title>EAP-TLS Computer Authetication Failing</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-computer-authetication-failing/m-p/4861176#M582430</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have configured ise to accept both machine and user certificate authentications and mab device management.&lt;BR /&gt;The user and mab certificate authentications are working properly, so both the ISE, switch and supplicant side configuration of the pc are ok.&lt;BR /&gt;Authentications with computer certificate on the other hand do NOT work, my client generated and manages the certificates from Intune, and as CN it passes me the GUID of intune and as SAN the machine name, unfortunately though I get denies because I think the ise can't read/find in AD the machine name and so the process fails.&lt;BR /&gt;I have already done the integration of Intune as external MDM but I don't understand how to unlock this situation, does anyone have any ideas?&lt;BR /&gt;I'm mainly investigating the supplicant and the certificate structure, but I don't understand what it could be and how I could fix the configuration (for some reason client doesn't want to pass the device id as CN but wants the GUID)&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 07:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-computer-authetication-failing/m-p/4861176#M582430</guid>
      <dc:creator>MaErre21325</dc:creator>
      <dc:date>2023-06-23T07:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS Computer Authetication Failing</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-computer-authetication-failing/m-p/4861510#M582435</link>
      <description>&lt;P&gt;If the machine name is populated in the SAN then I think you can change the certificate attribute in the certificate authentication policy (CAP) in ISE to lookup for the SAN rather than the CN value. To change that click on the drop down menu and select Subject Alternative Name - DNS or Other Name.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-computer-authetication-failing/m-p/4861510#M582435</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-23T15:51:13Z</dc:date>
    </item>
  </channel>
</rss>

