<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I don't thinlk it is possible in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-certificate-attribute/m-p/2425021#M88133</link>
    <description>&lt;P&gt;I don't thinlk it is possible to check the Certificate for the Template that was used to create it.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Add on:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When the user authenticates with either PEAP or EAP-FAST, against AD external ID store then ACS performs an additional action. It searches the cache for the users &lt;CODE class="cExPlain"&gt;Calling-Station-Id.&lt;/CODE&gt; If it is found then &lt;B class="cBold"&gt;Was-Machine-Authenticated&lt;/B&gt; attribute is set to true on the session context, otherwise set to false. &lt;A name="wp1254977" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;For the above to function correctly, the user authentication request should contain the &lt;CODE class="cExPlain"&gt;Calling-Station-Id&lt;/CODE&gt;. In case it does not, the &lt;B class="cBold"&gt;Was-Machine-Authenticated&lt;/B&gt; attribute shall be set to false.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254978" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;The administrator can add rules to authorization policies that are based on AD GM attribute and on Machine authentication required attribute. Any rule that contains these two attributes will only apply if the following conditions are met:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254979" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="17" /&gt;MAR feature is enabled&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254980" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="17" /&gt;Machine authentication in the authenticating protocol settings is enabled&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254981" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="17" /&gt;External ID store is AD&lt;/P&gt;</description>
    <pubDate>Thu, 20 Mar 2014 03:34:33 GMT</pubDate>
    <dc:creator>Naveen Kumar</dc:creator>
    <dc:date>2014-03-20T03:34:33Z</dc:date>
    <item>
      <title>ACS Certificate Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-certificate-attribute/m-p/2425020#M88131</link>
      <description>&lt;P&gt;Hi Cisco Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question about Cisco ACS 5.3.0.&lt;/P&gt;&lt;P&gt;I like to check Certificates for WLAN users.&lt;/P&gt;&lt;P&gt;Currently I use mashine certificates to autheticate my notebooks trying to enter my corporate WLAN.&lt;/P&gt;&lt;P&gt;Now we like to also autheticate user Iphones and Ipads and like to use the same Issuing CA to enroll the Certificates.&lt;/P&gt;&lt;P&gt;The idea was to create a new Certificate Template to distinguish normal corporate Notebooks from corporate Ipads.&lt;/P&gt;&lt;P&gt;Is it possible to check the Certificate for the Template that was used to create it?&lt;/P&gt;&lt;P&gt;I allready found the possibility to check for combound conditions to check some Certificate attributes like the following.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/1/4/180412-Certificate%20Attributes.jpg" alt="Certificate Attributes.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But is it also possible to check for the Template that was used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;With kind regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Benedikt&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-certificate-attribute/m-p/2425020#M88131</guid>
      <dc:creator>benediktdiehl</dc:creator>
      <dc:date>2019-03-11T04:23:10Z</dc:date>
    </item>
    <item>
      <title>I don't thinlk it is possible</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-certificate-attribute/m-p/2425021#M88133</link>
      <description>&lt;P&gt;I don't thinlk it is possible to check the Certificate for the Template that was used to create it.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Add on:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When the user authenticates with either PEAP or EAP-FAST, against AD external ID store then ACS performs an additional action. It searches the cache for the users &lt;CODE class="cExPlain"&gt;Calling-Station-Id.&lt;/CODE&gt; If it is found then &lt;B class="cBold"&gt;Was-Machine-Authenticated&lt;/B&gt; attribute is set to true on the session context, otherwise set to false. &lt;A name="wp1254977" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;For the above to function correctly, the user authentication request should contain the &lt;CODE class="cExPlain"&gt;Calling-Station-Id&lt;/CODE&gt;. In case it does not, the &lt;B class="cBold"&gt;Was-Machine-Authenticated&lt;/B&gt; attribute shall be set to false.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254978" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;The administrator can add rules to authorization policies that are based on AD GM attribute and on Machine authentication required attribute. Any rule that contains these two attributes will only apply if the following conditions are met:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254979" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="17" /&gt;MAR feature is enabled&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254980" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="17" /&gt;Machine authentication in the authenticating protocol settings is enabled&lt;/P&gt;&lt;P&gt;&lt;A name="wp1254981" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="17" /&gt;External ID store is AD&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 03:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-certificate-attribute/m-p/2425021#M88133</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2014-03-20T03:34:33Z</dc:date>
    </item>
  </channel>
</rss>

