<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TEAP - Always using Username/Password in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022281#M587539</link>
    <description>In this scenario I don’t think you can with TEAP. In the “non-TEAP” flows you can configure User or Computer authentication but it’s a single EAP transaction, no chaining here.&lt;BR /&gt;</description>
    <pubDate>Wed, 21 Feb 2024 22:54:07 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-02-21T22:54:07Z</dc:date>
    <item>
      <title>TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022204#M587527</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm labbing up some 802.1x authentication scenarios.&amp;nbsp; We need to support both piv/cert auth and username/passwords (user forgets their card etc).&amp;nbsp; What I'm finding is whenever in the TEAP config i give it the option to use Secured Password, it always uses it even though it's the second choice.&amp;nbsp; Whenever i set them both to Smart Card or other certificate, understandably it uses Smartcard or other certificate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The expected behavior i'm looking for is if the client has a cert / piv etc, that identity source would be attempted first.&amp;nbsp; Only if the endpoint / user doesn't have a cert would it then fall back to username/password.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the other settings not shown i have the root cert checked so it's validated.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is what i'm currently seeing the expected behavior or is there something wrong.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 19:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022204#M587527</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-02-21T19:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022212#M587529</link>
      <description>&lt;P&gt;Credential guard enabled?&amp;nbsp; Why use passwords at all?&amp;nbsp; Why not always certificates?&lt;/P&gt;
&lt;P&gt;I also don't think it works like this.&amp;nbsp; The second auth type is the "second identity" with TEAP.&amp;nbsp; Its not a try certificate first then try username/password.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 20:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022212#M587529</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-02-21T20:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022214#M587530</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289" target="_self"&gt;someone had a discussion about this a while back&lt;/A&gt; - the Windows Supplicant is a bit weird - IIRC, Primary Authentication actually refers to the User Auth, and Secondary Authentication refers to the Machine Auth. And it should be EAP-TLS for both. Windows and Credential Guard will be a problem (hence why PEAP my not work, and can't be a fallback).&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 20:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022214#M587530</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-02-21T20:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022224#M587532</link>
      <description>&lt;P&gt;i would love to require staff to always use PIV auth but folks lose their cards, cards break, etc.....&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 20:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022224#M587532</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-02-21T20:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022241#M587535</link>
      <description>&lt;P&gt;So what do people do where the computer will have a cert from an enterprise PKI.&amp;nbsp; We can use that cert to validate the computer but on the user side they may or may not have a piv card for reasons above and think like computers in some lab where you can't bring your piv card with you but you need to username/password onto them.&amp;nbsp; As best i can tell, the supplicate on a windows box can only be configured for one or the other....that is either use cert for both the user/computer or use username/password.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 21:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022241#M587535</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-02-21T21:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022251#M587537</link>
      <description>You have multiple authz scenarios for this use-case, computer auth only, computer and user auth succeeded, computer auth failed, computer auth succeeded and user auth failed, etc&lt;BR /&gt;</description>
      <pubDate>Wed, 21 Feb 2024 21:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022251#M587537</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-02-21T21:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022275#M587538</link>
      <description>&lt;P&gt;This is where i'm getting hung.&amp;nbsp; For windows computers we can pretty much for certain say it will have a cert.&amp;nbsp; Now multiple types of users could walk up to this same computer.&amp;nbsp; Some may username/password auth and others may PIV auth.&amp;nbsp; How would you configure the windows native supplicant?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:19:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022275#M587538</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-02-21T22:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022281#M587539</link>
      <description>In this scenario I don’t think you can with TEAP. In the “non-TEAP” flows you can configure User or Computer authentication but it’s a single EAP transaction, no chaining here.&lt;BR /&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022281#M587539</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-02-21T22:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP - Always using Username/Password</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022283#M587540</link>
      <description>&lt;P&gt;Yeah throw TEAP out the window with what i now understand.&amp;nbsp; So now we go down the EAP side and you have 2 options.&amp;nbsp; You either configure it for "Secured Password (EAP-MSCHAP v2)"&amp;nbsp; OR "Smartcard Card or other Certificate".&amp;nbsp; Given the same scenario mentioned previously how would that play out?&amp;nbsp; Lets say we set it to Secured Password but the user uses their PIV card....&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 22:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-always-using-username-password/m-p/5022283#M587540</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-02-21T22:58:42Z</dc:date>
    </item>
  </channel>
</rss>

