08-04-2011 01:16 PM - edited 03-10-2019 06:16 PM
I'm trying to setup at iterative identity policy for EAP-TLS authentication. Basically I'd like one rule to be tested then based on the result either proceed to authorization policy evaluation or go to the next identity policy rule.
For example, I have a certificate with no SubjAltName values and a dNSHostName in the subject, issued by a Win2008 R2 CA. I'm actually expecting identity matching to fail for this particular certificate, by the way.
I have a list of cert-auth based identity policies, each tied to a unique certificate authentication profile. Resembles something like this -
Each policy rule matches 'EAP-TLS' as the eap auth method and 'x509_PKI' as the auth method.
I've tried re-arranging the order of the identity policy rules. I've also tried altering the values for the Advanced Options (continue vs. reject vs. drop) if auth fails, user not found, or process failed.
Regardless, I find that for the certificate in question identity policy evaluation never goes past the 1st rule. In the case of the no SAN / dNSHostName subject certificate, identity policy evaluation essentially stops b/c 'principal username attribute is missing in client certificate'. While I expect this to happen, my expectation is that the identity policy evauation process will go on to rule #2. However it does not.
It's very possible that I'm defining these policies in correctly. Hopefully someone can lend some guidance.
Thanks.
08-04-2011 01:40 PM
There may be an underlying issue with my config. Here's what I'd like to accomplish with EAP-TLS -
Etc. etc.
Perhaps I need to define these among the Identity Store sequences...
08-08-2011 02:55 AM
Identity store sequences will not do the trick either, when you select certificate based it only allows you to choose one cert auth profile.
Can you provide more detail as to why you are trying to get this to work? It seems as if you have the ability to deploy which cert template you choose.
I dont think this is possible after looking through the ACS.
Thanks,
Tarik
02-09-2014 02:32 PM
Please find the link below and verify the steps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide