<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic eap-tls without active directory in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705975#M11111</link>
    <description>&lt;P&gt;hello, &lt;/P&gt;&lt;P&gt;i have a client who provides wireless access to separate entities in the same building.&lt;/P&gt;&lt;P&gt;Right now he's using LEAP and ACS database.  Now he would like to move toward eap-tls because it's the most secured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually, I install eap-tls within a active directory and distribute machine certificate via policy.  Now the problem is that his laptops are not in a Active directory domain because they come from unrelated entities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My idea was to use a fictionnal active directory just for the database purpose, and download machine certificate manually via the web.  (the client gets his hand on each laptop to configure LEAP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody have a bright idea to deploy machine certificate without active directory;  I think that no matter what, we need a database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank your for your suggestions.&lt;/P&gt;</description>
    <pubDate>Sat, 03 Jul 2021 20:16:46 GMT</pubDate>
    <dc:creator>lionellemaire</dc:creator>
    <dc:date>2021-07-03T20:16:46Z</dc:date>
    <item>
      <title>eap-tls without active directory</title>
      <link>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705975#M11111</link>
      <description>&lt;P&gt;hello, &lt;/P&gt;&lt;P&gt;i have a client who provides wireless access to separate entities in the same building.&lt;/P&gt;&lt;P&gt;Right now he's using LEAP and ACS database.  Now he would like to move toward eap-tls because it's the most secured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually, I install eap-tls within a active directory and distribute machine certificate via policy.  Now the problem is that his laptops are not in a Active directory domain because they come from unrelated entities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My idea was to use a fictionnal active directory just for the database purpose, and download machine certificate manually via the web.  (the client gets his hand on each laptop to configure LEAP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody have a bright idea to deploy machine certificate without active directory;  I think that no matter what, we need a database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank your for your suggestions.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 20:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705975#M11111</guid>
      <dc:creator>lionellemaire</dc:creator>
      <dc:date>2021-07-03T20:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: eap-tls without active directory</title>
      <link>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705976#M11112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since your customer is the control point, then putting in an AD under his control would be a good idea...he'd own the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you could partition the tree such that each of his customers is an OU, and set up each user as you normally would. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Define access according to the user's OU as a group. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe it would be a good way to go. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without an AD, you can have the users acces the CA directly (&lt;A class="jive-link-custom" href="http://" target="_blank"&gt;http://&lt;/A&gt;&lt;HOSTNAME_OR_ADDRESS&gt;/certsrv for a Microsoft CA)&lt;/HOSTNAME_OR_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR, you did say your customer has access to the laptops for configuration, you could just install the certs manually when you set them up for EAP-TLS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR, if you can talk your customer into using EAP-FAST, it's also very secure and doesn't require a user-side certificate (and is compatible with wireless IP Phones, which EAP-TLS is not, AFAIK).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Nov 2006 16:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705976#M11112</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2006-11-26T16:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: eap-tls without active directory</title>
      <link>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705977#M11113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;The client certainly will not impose AD on his customers so I will just install the certificate manually and do machine authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the certificates certify a username.  I tried setting that username in the ACS database but now what password should I use in ACS ?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think the PC will send a password.  &lt;/P&gt;&lt;P&gt;Do you think that could work ? &lt;/P&gt;&lt;P&gt;the pc says cn=host/test_pc and the ACS checks that and grants access provided they both trust the same CA ? &lt;/P&gt;&lt;P&gt;I think that the ACS will try to check the password of cn=host/test_pc if ACS has this username in its local database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2006 10:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-tls-without-active-directory/m-p/705977#M11113</guid>
      <dc:creator>lionellemaire</dc:creator>
      <dc:date>2006-11-28T10:48:00Z</dc:date>
    </item>
  </channel>
</rss>

