<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Accept certificates without validating purpose will break 802. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347479#M598986</link>
    <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;this is one of those questions that, once I read it, I couldn't get out of my head.&amp;nbsp; :&amp;nbsp; )&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;At this exact moment, I don't have a Use Case for it yet, but thank you for pointing it out; some checkboxes end up going unnoticed by me, and this was one of them.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Some &lt;STRONG&gt;Bug ID&lt;/STRONG&gt; references:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvz78531" target="_blank" rel="noopener"&gt;CSCvz78531 Add human readable outputs in the live logs detailed report when KU or EKU attributes are missing&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz78547" target="_blank" rel="noopener"&gt;CSCvz78547 ISE admin guide should specify that there is a way to bypass the mandatory Key Usage&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;and this old Post:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/cisco-bug-discussions/cscvz78531-eap-tls-human-readable-live-log-error-messages-needed/td-p/4477061" target="_blank" rel="noopener"&gt;EAP-TLS human readable live log error messages needed&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;"&lt;EM&gt; ... Per &lt;STRONG&gt;TAC&lt;/STRONG&gt; the requirement/check for &lt;STRONG&gt;Key Encipherment&lt;/STRONG&gt; was added in &lt;STRONG&gt;ISE 2.3&lt;/STRONG&gt; ...&lt;/EM&gt; "&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note:&amp;nbsp;I added your question to my list; if I find the answer, I'll post it here !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Best regards&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Nov 2025 00:29:11 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2025-11-17T00:29:11Z</dc:date>
    <item>
      <title>ISE Accept certificates without validating purpose will break 802.1AR</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5341246#M598671</link>
      <description>&lt;P&gt;Does anyone know what a valid use case is for unchecking this box?&lt;/P&gt;
&lt;P&gt;According to my experience, it tries to enforce RFC 5280. But in reality, unchecking this box can break 802.1X authentications. In particular, devices that are authenticating with 802.1AR IDevID certificates. I validated this with one vendor (Axis) who implement 802.1AR certs, and according to the IEEE document for that spec, there is no requirement for an EKU (and Axis don't include it) and the spec also says NOT to include the Key Usage for these certs.&lt;/P&gt;
&lt;P&gt;802.1AR is a very good initiative to make onboarding of devices easier using EAP-TLS - there seems to be a disconnect somewhere between the RFC 5280's pipe dream of better security, and the IEEE's vision of plug and play EAP-TLS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bottom line - don't uncheck that box unless you know 100% why you are doing it.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1761187438120.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/254071i291B5D21F9846A44/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1761187438120.png" alt="ArneBier_0-1761187438120.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 02:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5341246#M598671</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-10-23T02:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Accept certificates without validating purpose will break 802.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347479#M598986</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;this is one of those questions that, once I read it, I couldn't get out of my head.&amp;nbsp; :&amp;nbsp; )&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;At this exact moment, I don't have a Use Case for it yet, but thank you for pointing it out; some checkboxes end up going unnoticed by me, and this was one of them.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Some &lt;STRONG&gt;Bug ID&lt;/STRONG&gt; references:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvz78531" target="_blank" rel="noopener"&gt;CSCvz78531 Add human readable outputs in the live logs detailed report when KU or EKU attributes are missing&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz78547" target="_blank" rel="noopener"&gt;CSCvz78547 ISE admin guide should specify that there is a way to bypass the mandatory Key Usage&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;and this old Post:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/cisco-bug-discussions/cscvz78531-eap-tls-human-readable-live-log-error-messages-needed/td-p/4477061" target="_blank" rel="noopener"&gt;EAP-TLS human readable live log error messages needed&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;"&lt;EM&gt; ... Per &lt;STRONG&gt;TAC&lt;/STRONG&gt; the requirement/check for &lt;STRONG&gt;Key Encipherment&lt;/STRONG&gt; was added in &lt;STRONG&gt;ISE 2.3&lt;/STRONG&gt; ...&lt;/EM&gt; "&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note:&amp;nbsp;I added your question to my list; if I find the answer, I'll post it here !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Best regards&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 00:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347479#M598986</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-11-17T00:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Accept certificates without validating purpose will break 802.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347481#M598987</link>
      <description>&lt;P&gt;In my books, this checkbox is called the RFC 5280 kill switch.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 01:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347481#M598987</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-11-17T01:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Accept certificates without validating purpose will break 802.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347489#M598990</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I loved that my friend !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 02:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-accept-certificates-without-validating-purpose-will-break/m-p/5347489#M598990</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-11-17T02:19:41Z</dc:date>
    </item>
  </channel>
</rss>

