<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wireless Authentication - Cisco ISE using LDAP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-authentication-cisco-ise-using-ldap/m-p/4182188#M17526</link>
    <description>&lt;P&gt;I am using 5520 WLC and AP 9120 with 8.1.102.0 code to authenticate clients via ISE 2.6 using Novel LDAP as identity source.&lt;/P&gt;&lt;P&gt;It appears that MSCHAPv1/v2, EAP-MSCHAPV2 and PEAP are not supported on LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise the possible ways to do it. Its urgent and time sensitive project.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 19:46:47 GMT</pubDate>
    <dc:creator>atsetheodros</dc:creator>
    <dc:date>2021-07-05T19:46:47Z</dc:date>
    <item>
      <title>Wireless Authentication - Cisco ISE using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-cisco-ise-using-ldap/m-p/4182188#M17526</link>
      <description>&lt;P&gt;I am using 5520 WLC and AP 9120 with 8.1.102.0 code to authenticate clients via ISE 2.6 using Novel LDAP as identity source.&lt;/P&gt;&lt;P&gt;It appears that MSCHAPv1/v2, EAP-MSCHAPV2 and PEAP are not supported on LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise the possible ways to do it. Its urgent and time sensitive project.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-cisco-ise-using-ldap/m-p/4182188#M17526</guid>
      <dc:creator>atsetheodros</dc:creator>
      <dc:date>2021-07-05T19:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication - Cisco ISE using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-cisco-ise-using-ldap/m-p/4182356#M17527</link>
      <description>&lt;P&gt;The issue is with the passwords in LDAP - (the passwords should not be transmitted, but rather, a hash is transmitted).&lt;/P&gt;
&lt;P&gt;LDAP repositories are suited to PAP/ASCII password exchanges. And neither of those are supported inner EAP methods &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way you could get those LDAP identities into ISE itself? It might require some coding and regular sync, but if the username and password existed in ISE, then you can do EAP and MSCHAPv1/2 inner method.&lt;/P&gt;
&lt;P&gt;The obvious solution would be to migrate the users to Active Directory ... instead of Novel &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe there are &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/HOW-TO-Configure-Generic-LDAP-w-MSCHAPv2-Based-Authentication-in-Identity-Engines" target="_self"&gt;people on the internet&lt;/A&gt; who have got this to work -but they had to create password hashes for all of the accounts and then store this hashed password as an additional attribute per user. Quite clever - it means that ISE would have to retrieve that attribute during authentication, and not the regular user password. I cannot verify this but it sounds very promising.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 20:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-cisco-ise-using-ldap/m-p/4182356#M17527</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-11-11T20:14:54Z</dc:date>
    </item>
  </channel>
</rss>

