<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ciphers suites for EAP-TLS on windows 10/11 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5247208#M594206</link>
    <description>&lt;P&gt;Thank you for posting the answer to this! I referenced this post in &lt;A href="https://cs.co/ise-berg#windows" target="_blank"&gt;https://cs.co/ise-berg#windows&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2025 23:00:58 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2025-01-14T23:00:58Z</dc:date>
    <item>
      <title>Ciphers suites for EAP-TLS on windows 10/11</title>
      <link>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5244396#M594053</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was reading this kb regarding ISE 3.3 and Ciphers &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-33/221570-configure-ciphers-in-ise-3-3-and-later.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-33/221570-configure-ciphers-in-ise-3-3-and-later.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and I was wondering if some of you know where to restrict the ciphers and protocols used by the Windows 10/11 supplicant for EAP-TLS. I found some registry keys but not sure if this is exactly what I need and which one exactly:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols&lt;/LI&gt;
&lt;LI&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\CipherSuites&lt;/LI&gt;
&lt;LI&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers&lt;/LI&gt;
&lt;LI&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Any idea or feedback based on your experience?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5244396#M594053</guid>
      <dc:creator>REJR77</dc:creator>
      <dc:date>2025-01-07T13:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ciphers suites for EAP-TLS on windows 10/11</title>
      <link>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5244409#M594054</link>
      <description>&lt;P&gt;Following.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 14:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5244409#M594054</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-07T14:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ciphers suites for EAP-TLS on windows 10/11</title>
      <link>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5244547#M594066</link>
      <description>&lt;P&gt;Great question. Have you asked Microsoft or their Community forums too?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 20:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5244547#M594066</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-07T20:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Ciphers suites for EAP-TLS on windows 10/11</title>
      <link>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5246835#M594198</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I was able to get the following from microsoft&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On Windows 10/11, TLS settings and Cipher Suites configuration are important for network authentication such as EAP-TLS. Below are detailed instructions on how to modify these settings and answers to confirm that these registry entries work with EAP-TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Confirming the role of registry entries&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Here are the roles of the registry entries you mentioned and whether they affect EAP-TLS: &lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;&lt;STRONG&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Purpose: Used to enable or disable specific TLS protocol versions (e.g. TLS 1.0, TLS 1.1, TLS 1.2, TLS 1.3).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Relevance to EAP-TLS: Yes, EAP-TLS relies on the SCHANNEL stack, so the settings in this registry entry affect the protocol version used by EAP-TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;How to configure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;The subsections Client and Server define the enabled state of the protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Add the DWORD values Enabled and DisabledByDefault:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Enabled = 1 Enables the protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;DisabledByDefault = 1 to disable the protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;For example, to disable TLS 1.0:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client &lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;DWORD: DisabledByDefault = 1 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;DWORD: Enabled = 0 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\CipherSuites&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Function: Defines the list of cipher suites supported by SCHANNEL.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Is relevant for EAP-TLS: Yes, this controls the cipher suites used by EAP-TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;How to configure:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Windows does not include this registry entry by default. If you need to restrict ciphersuites, you can add it via Group Policy or manually.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;The format is the name of the cipher suite (e.g. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;For example, to disable some cipher suites, you can manually add unneeded suites to this item and set the value to zero.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Function: Used to enable or disable specific encryption algorithms (e.g. AES, DES, RC4).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Relevance to EAP-TLS: Yes, this item affects the choice of encryption algorithms for EAP-TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;How to configure:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Add a child (e.g. AES 256/128) and set the DWORD value Enabled = 0 or 1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;For example, to disable RC4 encryption:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;DWORD: Enabled = 0 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Purpose: Defines the cipher suite prioritization for TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Relevance to EAP-TLS: Yes, this item is used to control cipher suite prioritization and affects EAP-TLS negotiation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;How to configure:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;This is managed by Group Policy and may be overridden by manual editing.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;The Functions value contains the cipher suite's priority order, separated by semicolons.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384;TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA25&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Disclaimer: Modifying the registry or workgroups is usually geared towards advanced users, administrators, and IT professionals, and it can help fix some problems, however, improper registry modifications can cause serious problems. Therefore, please make sure to strictly follow the steps below. For further protection, make a backup of the registry before modifying it. For more information on how to backup and restore the registry ref:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-prewrap="true"&gt;&lt;SPAN&gt;&lt;A title="support.microsoft.com" href="https://support.microsoft.com/en-us/topic/how-to-back-up-and-restore-the-registry-in-windows-855140ad-e318-2a13-2829-d428a2ab0692" target="_blank" rel="noopener"&gt;How to back up and restore the registry in Windows - Microsoft Support&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 08:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5246835#M594198</guid>
      <dc:creator>REJR77</dc:creator>
      <dc:date>2025-01-14T08:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ciphers suites for EAP-TLS on windows 10/11</title>
      <link>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5247208#M594206</link>
      <description>&lt;P&gt;Thank you for posting the answer to this! I referenced this post in &lt;A href="https://cs.co/ise-berg#windows" target="_blank"&gt;https://cs.co/ise-berg#windows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 23:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ciphers-suites-for-eap-tls-on-windows-10-11/m-p/5247208#M594206</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2025-01-14T23:00:58Z</dc:date>
    </item>
  </channel>
</rss>

