<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC - Posture assessment for non-admin user in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657904#M747924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Yes, you need 2 subtree, Trust1 and Trust2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first you have to sign these two files, if not signed.&amp;nbsp; The &lt;STRONG style="border-collapse: collapse; font-size: 12px; list-style-type: none; font-weight: bold;"&gt;"certificate"&lt;/STRONG&gt;&lt;STRONG style="border-collapse: collapse; font-size: 12px; list-style-type: none; font-weight: bold;"&gt; &lt;/STRONG&gt;is a field from the signed file , for.example&amp;nbsp; the 2.5.4.3 means:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.5.4.3 - COMMON_NAME&lt;/P&gt;&lt;P&gt;witch is the signer name (right click -&amp;gt; Digital Signatures-&amp;gt; Signer Name) . At a Computer Associates (CA) virus installer it is simple "CA".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The FileversionInfo is a simple value from a file&amp;nbsp; (Right Click -&amp;gt; Properties-&amp;gt; Version)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The accepted values for Certificate/Fileversioninfo are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: bold; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;Supported Value Names Under Certificate&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401532"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.3 - COMMON_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401533"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.4 - SUR_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401534"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.5 - DEVICE_SERIAL_NUMBER&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401535"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.6 - COUNTRY_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401536"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.7 - LOCALITY_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401537"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.8 - STATE_OR_PROVINCE_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401538"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.9 - STREET_ADDRESS&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401539"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.10 - ORGANIZATION_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401540"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.11 - ORGANIZATIONAL_UNIT_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401541"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.12 - TITLE&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401542"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.13 - DESCRIPTION&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401543"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.14 - SEARCH_GUIDE&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401544"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.15 - BUSINESS_CATEGORY&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401545"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.16 - POSTAL_ADDRESS&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401546"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.17 - POSTAL_CODE&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401547"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.18 - POST_OFFICE_BOX&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401548"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.19 - PHYSICAL_DELIVERY_OFFICE_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401549"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.20 - TELEPHONE_NUMBER&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401550"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: bold; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;Supported Value Names Under FileVersionInfo&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401551"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;ProductName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401552"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;CompanyName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401553"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;FileDescription&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401554"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;FileVersion&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401555"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;InternalName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401556"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;LegalCopyright&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401557"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;OriginalFileName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401558"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;ProductVersion&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401559"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Comments&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401560"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;LegalTrademarks&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401561"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;PrivateBuild&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401562"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;SpecialBuild&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401566"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Jun 2011 18:28:51 GMT</pubDate>
    <dc:creator>Attila Horvath</dc:creator>
    <dc:date>2011-06-20T18:28:51Z</dc:date>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657899#M747919</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I tried to set up the NAC so that if an application is not running, it will be launched automatically by the agent. Or if a software is not installed, the setup file will be downloaded to the computer and installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works fine when the user has admin privilege, but the “agent stub” cannot launch the application when the user doesn’t have the right privilege.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; “Agent stub” was installed&amp;nbsp; manually with admin privilege on the computer. Now the CCA agent&amp;nbsp; can be installed with non-admin user , the IP address is also renewed&amp;nbsp; even if the user doesn’t have the required privilege.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can i&amp;nbsp; copy file, install and launch programs on non-admin user ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657899#M747919</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2020-02-21T12:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657900#M747920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am posing the same question to Cisco support right now and I need an answer soon. We all know you don’t give a non –admin user local admin rights on the pc. I have a Nac 4.8.1 soon to be 4.8.2 real ip layer three deployment. You no longer see the option to download the CCAStubAgent.exe on the Cam manager. I really need a senior member of TAC to chime in and answer the question how do you deploy agents today on windows machine with the latest nac build. Please tell me someone did not overlook this in the latest code. I was able to install the agent as admin user and then login as non-admin. The agent works as expected at this point but I can not touch 2000 machines. No I do not have a software deployment suite.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 14:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657900#M747920</guid>
      <dc:creator>Bobby Meador</dc:creator>
      <dc:date>2011-06-16T14:36:31Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657901#M747921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've seen this from cisco &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;============&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Launch Programs Without Admin Privileges&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The executable must have:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;•A valid digital signature signed by certificates with specific field value(s)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;•File version information with specific item value(s)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Note also that:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;•The executable must be signed with a code signing certificate with a proper chain of certificates. The code signing certificate must be installed on the client machine.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;•The root certificate must also be installed on the client machine and must be in the Trusted Root Certification Authority on Windows.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;•You must create a registry key that is particular to the executable being run in addition to installing the certificate&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;============&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to get free code signing certificate for test (PFX file), don't know if it's ok.&lt;/P&gt;&lt;P&gt;the certificate appears under "&lt;EM&gt;Trusted Root Certification Authority "&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I signed the exe file with SignGUI and now, i can see the tab "digital signature" from the exe file property&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what registry key i need to create.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anyone who can say if it's ok with free certificate and what should be added on registry?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 15:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657901#M747921</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-06-16T15:44:40Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657902#M747922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;See this:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/45/cam/m_agent.html#wpxref78883"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/45/cam/m_agent.html#wpxref78883&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 style="font-size: 13px; color: #000000; text-decoration: none; font-weight: bold; font-family: Arial, Helvetica, sans-serif; font-style: normal; font-variant: normal; margin-bottom: 7px; margin-left: -0.1in; margin-right: 0em; margin-top: 14px; text-align: left; text-indent: 0em; text-transform: none;"&gt;How the Agent Verifies Digital Signature and Trust on an Executable Program&lt;/H3&gt;&lt;P&gt; &lt;A name="wp1401519"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;On the client computers where the executables will run, you must add a Trust&lt;EM style="font-style: italic;"&gt;&lt;N&gt;&lt;/N&gt;&lt;/EM&gt; key in the registry under the Stub Service definition for the executable that you want to run under the Stub service. It is the administrator's responsibility to populate the required registry keys for the programs to be trusted by the Agent and Agent Stub. The Clean Access Agent Stub verifies the launch program for a trusted digital signature as follows:&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401520"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.65in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;&lt;STRONG&gt;1. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Verifies the digital signature - Ensures the digital signature is trusted.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401521"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.65in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;&lt;STRONG&gt;2. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Verifies the signer certificate information based on the information in the registry.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401522"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;The related registry structure appears as follows:&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401523"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;&lt;STRONG style="font-weight: bold;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCAAgentStub\Trust&lt;/STRONG&gt;&lt;EM style="font-style: italic; font-weight: normal;"&gt;&lt;N&gt;&lt;/N&gt;&lt;/EM&gt;\&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401524"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;&lt;STRONG style="font-weight: bold;"&gt;\Certificate\2.5.4.3&lt;/STRONG&gt; "Cisco Systems"&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401525"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;&lt;STRONG style="font-weight: bold;"&gt;\FileVersionInfo\ProductName&lt;/STRONG&gt; "Clean Access"&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401526"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;Where:&lt;/P&gt;&lt;P&gt; &lt;A name="wp1465463"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;EM style="font-style: italic; font-weight: normal;"&gt;&lt;N&gt;&lt;/N&gt;&lt;/EM&gt; is a numeric number.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401527"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;For the entries under &lt;STRONG style="font-weight: bold;"&gt;Certificate&lt;/STRONG&gt;, each value can be exact case-insensitive.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401528"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;For the entries under &lt;STRONG style="font-weight: bold;"&gt;FileVersionInfo&lt;/STRONG&gt;, each value must appear in the corresponding value in the file information stream, and can also be case-insensitive.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401529"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;All the entries under &lt;STRONG style="font-weight: bold;"&gt;Certificate&lt;/STRONG&gt; and &lt;STRONG style="font-weight: bold;"&gt;FileVersionInfo&lt;/STRONG&gt; must be satisfied (AND operations) to qualify as a trusted target.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401530"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;If any of the &lt;STRONG style="font-weight: bold;"&gt;Trust&lt;/STRONG&gt;&lt;EM style="font-style: italic; font-weight: normal;"&gt;&lt;N&gt;&lt;/N&gt;&lt;/EM&gt; chain is satisfied, the target is qualified to launch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 17:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657902#M747922</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-06-17T17:39:24Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657903#M747923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's suppose we need to launch tftpd (exe file : tftpd32.exe) and clamwin Antivirus, does it mean that we need to add &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trust1 under : &lt;STRONG style="font-weight: bold;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCAAgentStub&lt;/STRONG&gt; for tftp&lt;/P&gt;&lt;P&gt;and&amp;nbsp; Trust2 under : &lt;STRONG style="font-weight: bold;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCAAgentStub&lt;/STRONG&gt; for clamwin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-weight: bold;"&gt;and do we need to create&lt;/STRONG&gt;&lt;STRONG style="font-weight: bold;"&gt; &lt;/STRONG&gt;&lt;STRONG style="font-weight: bold;"&gt; "certificate" and "FileVersionInfo" ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-weight: bold;"&gt;what value should we use ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-weight: bold;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 14:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657903#M747923</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-06-20T14:18:01Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657904#M747924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Yes, you need 2 subtree, Trust1 and Trust2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first you have to sign these two files, if not signed.&amp;nbsp; The &lt;STRONG style="border-collapse: collapse; font-size: 12px; list-style-type: none; font-weight: bold;"&gt;"certificate"&lt;/STRONG&gt;&lt;STRONG style="border-collapse: collapse; font-size: 12px; list-style-type: none; font-weight: bold;"&gt; &lt;/STRONG&gt;is a field from the signed file , for.example&amp;nbsp; the 2.5.4.3 means:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.5.4.3 - COMMON_NAME&lt;/P&gt;&lt;P&gt;witch is the signer name (right click -&amp;gt; Digital Signatures-&amp;gt; Signer Name) . At a Computer Associates (CA) virus installer it is simple "CA".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The FileversionInfo is a simple value from a file&amp;nbsp; (Right Click -&amp;gt; Properties-&amp;gt; Version)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The accepted values for Certificate/Fileversioninfo are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: bold; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;Supported Value Names Under Certificate&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401532"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.3 - COMMON_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401533"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.4 - SUR_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401534"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.5 - DEVICE_SERIAL_NUMBER&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401535"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.6 - COUNTRY_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401536"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.7 - LOCALITY_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401537"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.8 - STATE_OR_PROVINCE_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401538"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.9 - STREET_ADDRESS&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401539"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.10 - ORGANIZATION_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401540"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.11 - ORGANIZATIONAL_UNIT_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401541"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.12 - TITLE&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401542"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.13 - DESCRIPTION&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401543"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.14 - SEARCH_GUIDE&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401544"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.15 - BUSINESS_CATEGORY&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401545"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.16 - POSTAL_ADDRESS&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401546"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.17 - POSTAL_CODE&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401547"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.18 - POST_OFFICE_BOX&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401548"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.19 - PHYSICAL_DELIVERY_OFFICE_NAME&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401549"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;2.5.4.20 - TELEPHONE_NUMBER&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401550"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: bold; margin-bottom: 6px; margin-left: 0em; margin-right: 0em; margin-top: 1px; text-align: left; text-decoration: none; text-indent: 0em; text-transform: none;"&gt;Supported Value Names Under FileVersionInfo&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401551"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;ProductName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401552"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;CompanyName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401553"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;FileDescription&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401554"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;FileVersion&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401555"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;InternalName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401556"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;LegalCopyright&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401557"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;OriginalFileName&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401558"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;ProductVersion&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401559"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Comments&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401560"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;LegalTrademarks&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401561"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;PrivateBuild&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401562"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7px; margin-left: 0.25in; margin-right: 0em; text-align: left; text-decoration: none; text-indent: -0.25in; text-transform: none;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;SpecialBuild&lt;/P&gt;&lt;P&gt; &lt;A name="wp1401566"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 18:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657904#M747924</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-06-20T18:28:51Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657905#M747925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to post all steps we did.&lt;/P&gt;&lt;P&gt;Please, correct if there's something wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1/ code signing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we asked for a free certificate from internet and we got a pfx file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we used a free tool (SignGUI) and got spc, cer and pvk file from the pfx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we launched signcode.exe to sign excutable files (clamwinTray.exe and tftpd32.exe)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we chose "custom" option and "selected from file" on digital signature wizard, we selected the spc file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we specified the location of pvk file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we selected sha1 as hash algorithm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- "all cerificates in the certification path, including the root certificate" was chosen under "certifcate in the certification path"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we got a message "digital signing wizard was completed successfully"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- from "digital signatures" tab of the executable file, we had "cerificate issued to certificate_usernac" and "cerificate issued by Root Agency"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2/ registry key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCAAgentStub, we created 2 subtree, Trust1 and Trust2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for trust1, we created &lt;/P&gt;&lt;P&gt;- new key : certificate&lt;/P&gt;&lt;P&gt;- new string value : name = 2.5.4.3, value = certificate_usernac&lt;/P&gt;&lt;P&gt;- new key : FileVersionInfo&lt;/P&gt;&lt;P&gt;- new string value : name = ProductName, value = ClamWin Antivirus &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for trust2, we created &lt;/P&gt;&lt;P&gt;- new key : certificate&lt;/P&gt;&lt;P&gt;- new string value : name = 2.5.4.3, value = certificate_usernac&lt;/P&gt;&lt;P&gt;- new key : FileVersionInfo&lt;/P&gt;&lt;P&gt;- new string value : name = ProductName, value = Tftpd32 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3/ NAC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we create "Application check" for ClamTray.exe and tftpd32.exe, operator = running, OS = Windows All, rule = automatically created&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we created new requirement with Launch Program&lt;/P&gt;&lt;P&gt;Program Name : SYSTEM_PROGRAMS\ClamWin\bin\ClamTray.exe for ClamWin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Program Name : SYSTEM_DRIVE\tftpd32.exe for tftp&lt;/P&gt;&lt;P&gt;OS = Windows XP (All)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- we configured "Requirement-rules"&lt;/P&gt;&lt;P&gt;- we configured "Role-Requirement"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we always get "Stub Agent failed to launch ... "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything wrong or missing ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know also if&amp;nbsp; it can be used on windows with language other than english.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking forward to hearing from you soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Best Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 14:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657905#M747925</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-06-21T14:58:38Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657906#M747926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems to me the steps are OK. The english language is not required, we tried with Hungarian XP lanuage &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Stub Agent failed to launch ..."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stub agent? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In nac 4.7 and 4.8 the stub agent is obsoloted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which NAC version ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And one more thing, at &lt;STRONG style="font-weight: bold;"&gt;NACAgentCFG.xml you have to set&amp;nbsp; the &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SignatureCheck to 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-size: 11px;"&gt; &lt;SIGNATURECHECK&gt;1&lt;/SIGNATURECHECK&gt; &lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_agntd.html#wp1348376"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_agntd.html#wp1348376&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 17:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657906#M747926</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-06-21T17:35:36Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657907#M747927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're using nac ver4.1.1 &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; (we have to use it for the moment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the document, it is mentionned :&lt;/P&gt;&lt;P&gt;"The root certificate must also be installed on the client machine and must be in the Trusted Root Certification Authority on Windows."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please tell how to do and check this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After code-signing the executable, we had the following message when checking the certificate from file property&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"this certificate cannot be verified up to a trusted certification authority"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to fix ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking forward to hearing from you soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2011 08:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657907#M747927</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-06-22T08:11:47Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657908#M747928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;According to this page:&lt;/P&gt;&lt;P&gt;&lt;A href="http://blogs.msdn.com/b/saurabh_singh/archive/2007/11/07/you-get-a-security-alert-when-you-try-to-access-an-ssl-enabled-web-site-when-certificate-has-been-issued-by-an-internal-root-ca.aspx"&gt;http://blogs.msdn.com/b/saurabh_singh/archive/2007/11/07/you-get-a-security-alert-when-you-try-to-access-an-ssl-enabled-web-site-when-certificate-has-been-issued-by-an-internal-root-ca.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you signed your files with a certificate (root CA), this certificate must exist at Client's &lt;/P&gt;&lt;P&gt;Trusted Root Certification Authorities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when you click on your signes file's properties -&amp;gt; Digital signatures -&amp;gt; Details -&amp;gt; View certificate -&amp;gt; Certificate Chain you mustn't see a red cross at root (like here: &lt;A href="http://blogs.msdn.com/blogfiles/saurabh_singh/WindowsLiveWriter/Yougetasecurityalertwhenyoutrytoaccessa_834/image_thumb_5.png"&gt;http://blogs.msdn.com/blogfiles/saurabh_singh/WindowsLiveWriter/Yougetasecurityalertwhenyoutrytoaccessa_834/image_thumb_5.png&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If it not helps - I am sorry, but the certificates is not my speciality, in this case I am afraid you need a microsoft expert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attila &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2011 09:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657908#M747928</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-06-22T09:53:16Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657909#M747929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks indeed for all your replies, they are extermely helpful.&lt;/P&gt;&lt;P&gt;it was the certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to ask how to do in case the user (without admin privilige) needs to install a software for remediation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking forward to hearing from you soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2011 14:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657909#M747929</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-06-22T14:37:21Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657910#M747930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;You need the Launch program feature for remediation, as described here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/411/cam/m_agent.html#wp1290357"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/411/cam/m_agent.html#wp1290357&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Attila&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2011 07:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657910#M747930</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-06-23T07:10:18Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657911#M747931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Attila,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your reply and for this interesting URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for my late reply.&lt;/P&gt;&lt;P&gt;We've tested software setup and Antivirus update using non-admin user, it works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are going to test windows update and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have more question about OOB L3 and IP phone. We'll add other posts asking these. Please, send us your extremely helpful answer, as usual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 06:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657911#M747931</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-06-28T06:30:13Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657912#M747932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Read this one: &lt;A href="http://www.caysec.com/2008/06/cisco-nac-with-ip-phones.html"&gt;http://www.caysec.com/2008/06/cisco-nac-with-ip-phones.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;/and change this topic's state to answered &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;/&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2011 14:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657912#M747932</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-06-30T14:26:27Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657913#M747933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Attila.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about L3 OOB, is it possible to use L3 if the NAC is setup as OOB Virtual Gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i 've put this question in another discussion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2091996"&gt;https://supportforums.cisco.com/thread/2091996&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking Forward to hearing from you soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thans and Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 08:04:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657913#M747933</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-07-01T08:04:11Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657914#M747935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a question. i have server where the installation file is there, i have to run sign gui only on that place itself right?&lt;/P&gt;&lt;P&gt;not on all the systems?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 20:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657914#M747935</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2011-07-19T20:40:22Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657915#M747937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;It does not matter &lt;STRONG&gt;where&lt;/STRONG&gt;&lt;/SPAN&gt; do you run the gui, the only important that&lt;/P&gt;&lt;P&gt;your installation file must be signed with a &lt;SPAN style="text-decoration: underline;"&gt;client trusted&lt;/SPAN&gt; CA, and this sign&lt;/P&gt;&lt;P&gt;must described at client's registry based things above (see correct answer).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2011 07:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657915#M747937</guid>
      <dc:creator>Attila Horvath</dc:creator>
      <dc:date>2011-07-20T07:35:36Z</dc:date>
    </item>
    <item>
      <title>NAC - Posture assessment for non-admin user</title>
      <link>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657916#M747940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Attila,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are trying to setup a NAS as OOB RIP for both L2 and L3 adjacent users.&lt;/P&gt;&lt;P&gt;it is used as DHCP server for L2 users and it works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However for L3 adjacent users, we have some problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-&amp;nbsp; when static route to L3 unauthenticated users is added on the NAS, the&amp;nbsp; user cannot ping the untrusted interface of NAS unless we first launch&amp;nbsp; ping to this untrusted interface from the switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&amp;nbsp; - we removed the static route and added ARP for L3 unauthenticated&amp;nbsp; users network, we can ping the untrusted interface and the cisco Agent&amp;nbsp; pop-up. it seems to work, user can log and then listed under the online&amp;nbsp; users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3&amp;nbsp; - then, we apply ACL permitting only trafic the untrusted interface of&amp;nbsp; NAS, remediation servers, dhcp, domain, udp 67/68 on the branch router&amp;nbsp; (sub-interface of unauthenticated user) . we can ping the untrusted&amp;nbsp; interface but the cisco Agent doesn't pop-up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACL, we&amp;nbsp; tried to permit the trusted interface of NAS and we can have the popup window of cisco agent; it seems to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we'd&amp;nbsp; like to know what could be the reason it doesn't work when we add&amp;nbsp; static route on NAS (we've read from some documents static route should&amp;nbsp; be added on NAS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we&amp;nbsp; would like also to know why we cannot get agent popup when the trusted&amp;nbsp; interface is not permitted (cause no document we've read mentionned that&amp;nbsp; trusted interface should be permitted)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Looking forward to hearing from you soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jul 2011 08:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-posture-assessment-for-non-admin-user/m-p/1657916#M747940</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-07-25T08:50:07Z</dc:date>
    </item>
  </channel>
</rss>

