<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic We most typically do this in in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552135#M89686</link>
    <description>&lt;P&gt;We most typically do this in the context of implementing a product like Cisco's Identity Services Engine (ISE). ISE uses 802.1x and has the ability to check clients for things like a certificate during the authentication / posture assessment / remediation process.&lt;/P&gt;&lt;P&gt;It also acts as a RADIUS server and can dynamically push out Change of Authorization (CoA) to the authenticator (i.e switch or Wireless controller) in order to control things like client VLAN assignment and any access-lists you may want to apply.&lt;/P&gt;&lt;P&gt;On the client side, a supplicant is used to interact with the authenticator. You can use native supplicants from OS X or Windows etc. but we generally recommend use of Cisco's AnyConnect Secure Mobility client with its Network Access Module (NAM) as it's much more full-featured for that purpose.&lt;/P&gt;&lt;P&gt;You could also do 802.1x with certificate authentication and use a different backend authentication server (like a regular Cisco ACS or Microsoft Network Policy Server) but you would just get more basic authentication vs. the rich functionality ISE gives (albeit ISE costs a lot more &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ).&lt;/P&gt;&lt;P&gt;Have a look at this Youtube video for an example of setting up certificate authentication on ACS:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;https://www.youtube.com/watch?v=U7qWJ7bIMHA&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jul 2014 03:29:25 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-07-01T03:29:25Z</dc:date>
    <item>
      <title>How to authenticate with certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552133#M89681</link>
      <description>&lt;P&gt;&lt;EMBED height="0" id="xunlei_com_thunder_helper_plugin_d462f475-c18e-46be-bd10-327458d045bd" type="application/thunder_download_plugin" width="0"&gt;I wanna try to build a more secure LAN. I want every client (wired/wireless) to connect the network used a certificate not a user/password pair.&lt;/EMBED&gt;&lt;/P&gt;&lt;P&gt;But now, as i am a newbie, I don't know what to choose between TACACS+ and RADIUS. Because I have a Mac mini, maybe RADIUS is more suitable, but i don't know how to establish the CA.&lt;/P&gt;&lt;P&gt;Any help or suggestion will be appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552133#M89681</guid>
      <dc:creator>miaozhixu</dc:creator>
      <dc:date>2019-03-11T04:50:24Z</dc:date>
    </item>
    <item>
      <title>Refer " Certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552134#M89684</link>
      <description>&lt;P&gt;Refer " Certificate Authentication Profiles" from&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_man_id_stores.html#18226&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 03:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552134#M89684</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-07-01T03:16:29Z</dc:date>
    </item>
    <item>
      <title>We most typically do this in</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552135#M89686</link>
      <description>&lt;P&gt;We most typically do this in the context of implementing a product like Cisco's Identity Services Engine (ISE). ISE uses 802.1x and has the ability to check clients for things like a certificate during the authentication / posture assessment / remediation process.&lt;/P&gt;&lt;P&gt;It also acts as a RADIUS server and can dynamically push out Change of Authorization (CoA) to the authenticator (i.e switch or Wireless controller) in order to control things like client VLAN assignment and any access-lists you may want to apply.&lt;/P&gt;&lt;P&gt;On the client side, a supplicant is used to interact with the authenticator. You can use native supplicants from OS X or Windows etc. but we generally recommend use of Cisco's AnyConnect Secure Mobility client with its Network Access Module (NAM) as it's much more full-featured for that purpose.&lt;/P&gt;&lt;P&gt;You could also do 802.1x with certificate authentication and use a different backend authentication server (like a regular Cisco ACS or Microsoft Network Policy Server) but you would just get more basic authentication vs. the rich functionality ISE gives (albeit ISE costs a lot more &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ).&lt;/P&gt;&lt;P&gt;Have a look at this Youtube video for an example of setting up certificate authentication on ACS:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;https://www.youtube.com/watch?v=U7qWJ7bIMHA&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 03:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552135#M89686</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-07-01T03:29:25Z</dc:date>
    </item>
    <item>
      <title>Marvin    Thanks a lot. You</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552136#M89687</link>
      <description>&lt;P&gt;Marvin&lt;EMBED height="0" id="xunlei_com_thunder_helper_plugin_d462f475-c18e-46be-bd10-327458d045bd" type="application/thunder_download_plugin" width="0"&gt;&lt;/EMBED&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Thanks a lot. You gave me a very detail answer! As I have checked the price of ISE, I will make a decision on building a TACACS+ Server from source on my poor Mac mini.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 05:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552136#M89687</guid>
      <dc:creator>miaozhixu</dc:creator>
      <dc:date>2014-07-01T05:17:29Z</dc:date>
    </item>
    <item>
      <title>"Certificate Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552137#M89688</link>
      <description>&lt;P&gt;&lt;EMBED height="0" id="xunlei_com_thunder_helper_plugin_d462f475-c18e-46be-bd10-327458d045bd" type="application/thunder_download_plugin" width="0"&gt;"Certificate Authencation Profiles" just include detail on how to setup in MS Windows AD, but the "RADIUS Token identity sources" did help me a lot.&lt;/EMBED&gt;&lt;/P&gt;&lt;P&gt;Thanks very much!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 11:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-authenticate-with-certificate/m-p/2552137#M89688</guid>
      <dc:creator>miaozhixu</dc:creator>
      <dc:date>2014-07-01T11:19:31Z</dc:date>
    </item>
  </channel>
</rss>

