<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP Chaining - cert check only in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337018#M598459</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324869"&gt;@GRANT3779&lt;/a&gt;&amp;nbsp;yes, you can just check the certificates are valid and use EAP Chaining. You don't need to perform additional checks, such as lookup to an external ID source (i.e., AD).&lt;/P&gt;</description>
    <pubDate>Wed, 08 Oct 2025 19:17:31 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2025-10-08T19:17:31Z</dc:date>
    <item>
      <title>EAP Chaining - cert check only</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337017#M598458</link>
      <description>&lt;P&gt;Hi CSC&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to do use TEAP / EAP Chaining within ISE when using only the certificates as a check? Basically, just check cert is trusted and no other checks are done. Can the user and machine cert be chained using just this check? &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 19:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337017#M598458</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2025-10-08T19:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining - cert check only</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337018#M598459</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324869"&gt;@GRANT3779&lt;/a&gt;&amp;nbsp;yes, you can just check the certificates are valid and use EAP Chaining. You don't need to perform additional checks, such as lookup to an external ID source (i.e., AD).&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 19:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337018#M598459</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-08T19:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining - cert check only</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337019#M598460</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I guess one last question would be around the authentication policy. For the "user not found" option would this need to be set to continue rather than reject (or whatever it says)?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 19:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337019#M598460</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2025-10-08T19:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining - cert check only</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337022#M598461</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324869"&gt;@GRANT3779&lt;/a&gt;&amp;nbsp;I guess it depends on what you wish to achieve in that scenario? You could leave it as reject and have an authorisation rule "User failed and machine succeeded" and grant a level of access (restrict with DACL).&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 19:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-cert-check-only/m-p/5337022#M598461</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-08T19:29:39Z</dc:date>
    </item>
  </channel>
</rss>

