09-17-2018 09:12 AM
Hello,
We have a problem in the configuration of the Authentification Policy, im selecting EAP-TLS in order to force clients to use the certification that i exported from the ISE, but the endpoint can only authenticate using "PEAP (EAP-MSCHAPv2)" even if there is no rule for this protocol.
Thanks to help us.
Solved! Go to Solution.
09-17-2018 09:58 AM
09-17-2018 10:54 AM - edited 09-17-2018 10:55 AM
in EAP-TLS each client should have their own certificate. You shouldn't be trying to export a certificate from ISE and trying to get the client's to use it to authenticate EAP-TLS. Further more if you are trying something like this you need to export both the cert/private key and ensure the certificate has EKU client auth enabled.
09-17-2018 09:58 AM
09-17-2018 10:54 AM - edited 09-17-2018 10:55 AM
in EAP-TLS each client should have their own certificate. You shouldn't be trying to export a certificate from ISE and trying to get the client's to use it to authenticate EAP-TLS. Further more if you are trying something like this you need to export both the cert/private key and ensure the certificate has EKU client auth enabled.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide