<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152583#M590907</link>
    <description>&lt;P&gt;i am not understanding your question ?&lt;/P&gt;
&lt;P&gt;some certificates you can put a password etc.. but the password is not very helpful as it can be cracked ... what i am saying if you make it non exportable is good.. The best option is to use non exportable with TPM for best security ..&lt;/P&gt;
&lt;P&gt;**Please click on Helpful button if this was useful**&lt;/P&gt;
&lt;P&gt;you&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jul 2024 02:15:02 GMT</pubDate>
    <dc:creator>ccieexpert</dc:creator>
    <dc:date>2024-07-29T02:15:02Z</dc:date>
    <item>
      <title>Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS)</title>
      <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5151490#M590873</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;Current we plan testing&amp;nbsp;EAP-FAST (Eap-MSCHAPv2, Eap-TLS) authentication.&lt;/P&gt;
&lt;P&gt;By Machined join domain and get certificate to be trusted device. What if the another new machine imported certificate (export cert from PC trusted machined) , does it work or not for the new machine connection to ISE? thanks.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 08:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5151490#M590873</guid>
      <dc:creator>Da ICS16</dc:creator>
      <dc:date>2024-07-26T08:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS)</title>
      <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152063#M590886</link>
      <description>&lt;P&gt;Hi if you mark the certificate as non exportable it will provide protection, but if its not TPM protected, then a malware may be able to export it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best protection is to use TPM and not all machine have TPM (older ones), but alteast blocking private key export in your cert template is a good fall back..&lt;/P&gt;
&lt;P&gt;&lt;A href="https://polansky.co/blog/tpm-backed-certificates-windows/" target="_blank"&gt;https://polansky.co/blog/tpm-backed-certificates-windows/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;**Please click on Helpful button if this was useful**&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2024 04:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152063#M590886</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-27T04:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS)</title>
      <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152581#M590905</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1481123"&gt;@ccieexpert&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;If we do not put passkey on certificate and some one will perform this case, does it work?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 01:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152581#M590905</guid>
      <dc:creator>Da ICS16</dc:creator>
      <dc:date>2024-07-29T01:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS)</title>
      <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152583#M590907</link>
      <description>&lt;P&gt;i am not understanding your question ?&lt;/P&gt;
&lt;P&gt;some certificates you can put a password etc.. but the password is not very helpful as it can be cracked ... what i am saying if you make it non exportable is good.. The best option is to use non exportable with TPM for best security ..&lt;/P&gt;
&lt;P&gt;**Please click on Helpful button if this was useful**&lt;/P&gt;
&lt;P&gt;you&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 02:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152583#M590907</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-29T02:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS)</title>
      <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152584#M590908</link>
      <description>&lt;P&gt;OK understand. thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 02:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152584#M590908</guid>
      <dc:creator>Da ICS16</dc:creator>
      <dc:date>2024-07-29T02:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Testing EAP-FAST (Eap-MSCHAPv2, Eap-TLS)</title>
      <link>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152586#M590909</link>
      <description>&lt;P&gt;Your welcome:)&lt;/P&gt;
&lt;P&gt;**Please dont forget to rate as helpful and also accept as solution if this was indeed helpful**&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 02:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/testing-eap-fast-eap-mschapv2-eap-tls/m-p/5152586#M590909</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-29T02:36:04Z</dc:date>
    </item>
  </channel>
</rss>

