<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLAN 802.1x certificate based client authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781598#M252124</link>
    <description>&lt;P&gt;Ok. Thanks for the suggestion.&lt;/P&gt;&lt;P&gt;With respect to the already installed certificates on the ISE from factory, will these work for 802.1x client authentication?&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 18:58:48 GMT</pubDate>
    <dc:creator>fuhrersk8</dc:creator>
    <dc:date>2023-02-23T18:58:48Z</dc:date>
    <item>
      <title>WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4712169#M247592</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;We want implement a&amp;nbsp;WLAN with 802.1x certificate based client authentication. I am following the document&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;Understand and Configure EAP-TLS with a WLC and ISE&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;, but is there a way to automatically install the certificate on the client machines without having to go manually to each? Like for example, the clients downloading the certificate form the ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 22:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4712169#M247592</guid>
      <dc:creator>fuhrersk8</dc:creator>
      <dc:date>2022-10-27T22:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4712177#M247595</link>
      <description>&lt;P&gt;If all the clients are part of the domain, you can deploy the certificate using a GPO. &lt;A href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/distribute-certificates-to-client-computers-by-using-group-policy#:~:text=To%20distribute%20certificates%20to%20client%20computers%20by%20using%20Group%20Policy" target="_blank"&gt;https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/distribute-certificates-to-client-computers-by-using-group-policy#:~:text=To%20distribute%20certificates%20to%20client%20computers%20by%20using%20Group%20Policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you have non-domain devices, then you need to deploy it using a MDM solution. Explore your MDM vendor for more info on how to do.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://documentation.meraki.com/SM/Profiles_and_Settings/Certificates_Payload_(Pushing_Certificates)" target="_blank"&gt;Certificates Payload (Pushing Certificates) - Cisco Meraki&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/mem/intune/protect/certificates-trusted-root" target="_blank"&gt;Create trusted certificate profiles in Microsoft Intune | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.manageengine.com/mobile-device-management/help/certificate_management/mdm_certificate_repository.html" target="_blank"&gt;Certificate Management | ManageEngine Mobile Device Manager Plus&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 22:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4712177#M247595</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-10-27T22:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4712216#M247603</link>
      <description>&lt;P&gt;What Arshad said. Other options look at&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;securew2.com if you need a managed PKI&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;environment to do this&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 00:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4712216#M247603</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2022-10-28T00:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781598#M252124</link>
      <description>&lt;P&gt;Ok. Thanks for the suggestion.&lt;/P&gt;&lt;P&gt;With respect to the already installed certificates on the ISE from factory, will these work for 802.1x client authentication?&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 18:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781598#M252124</guid>
      <dc:creator>fuhrersk8</dc:creator>
      <dc:date>2023-02-23T18:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781696#M252129</link>
      <description>&lt;P&gt;I think you need to at least have domain services and pki in your environment to successfully do this.&amp;nbsp; The client along with the radius has to trust the certty chain.&amp;nbsp; You can always try and use whatever cert you are using on ISE for EAP, but you will have to then upload the chain to the device cert store, manually setup the profile etc.&amp;nbsp; Then you will have to figure out the policy to get all that to work.&lt;/P&gt;
&lt;P&gt;You didnt provide if you have a domain you are using, is GPO possible, do you have a CA, what is your radius server and are you currently doing PEAP?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 23:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781696#M252129</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-02-23T23:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781709#M252130</link>
      <description>Yes, we do have a domain and a CA. But first we are setting a PoC before implementation.&lt;BR /&gt;</description>
      <pubDate>Thu, 23 Feb 2023 23:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781709#M252130</guid>
      <dc:creator>fuhrersk8</dc:creator>
      <dc:date>2023-02-23T23:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: WLAN 802.1x certificate based client authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781735#M252132</link>
      <description>&lt;P&gt;For your PoC, you should validate that certificates (user or computer) are pushed to each domain joined machine.&amp;nbsp; Then your ISE should have a certificate installed from your CA (device, intermediates, and root) and make sure that cert is imported and used for EAP.&amp;nbsp; This helps with the two way trust.&amp;nbsp; Then you would push out a wireless profile via GPO for your test SSID and configure the policies in ISEe to authenticate the user/device cert.&lt;/P&gt;
&lt;P&gt;Take a look at some guides and blogs on ISE using EAP-TLS and that will help with the steps you need to perform for your PoC.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 02:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlan-802-1x-certificate-based-client-authentication/m-p/4781735#M252132</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-02-24T02:18:33Z</dc:date>
    </item>
  </channel>
</rss>

