cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3408
Views
3
Helpful
10
Replies

Certificate Authentication Profile (CAP) - Identity Store Query

dot1x
Level 3
Level 3

Hi Members,

When we have Certificate Authentication Profile setup and haven't setup Identity Sequence in Authentication Profile, which Identity Store would ISE look for attributes mentioned in CAP Policy?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

The certificate attribute designated for the user identity is used as the subject/user to lookup for groups/attributes in identity stores as specified in the authorization policy rules. They can be any internal or external identity stores configured in ISE.

View solution in original post

10 Replies 10

hslai
Cisco Employee
Cisco Employee

The certificate attribute designated for the user identity is used as the subject/user to lookup for groups/attributes in identity stores as specified in the authorization policy rules. They can be any internal or external identity stores configured in ISE.

What about the authentication part?

For Authentication, would it check the ID Store specified in Authorization rule?

hslai
Cisco Employee
Cisco Employee

It depends on Steps 3 ~ 5 of Add a Certificate Authentication Profile

In case that no identity store chosen in Step 3, then ISE uses those certificates designed for client authentication in Trusted Certificates only.

Thanks hslai.

Could you please have a look at the attached CAP Profile?

Would it be checking ID Store specified in Authorization Rule?

If yes, what happens during Authentication? How would the user get authenticated?CAP Profile.JPG

hslai
Cisco Employee
Cisco Employee

The "Identity Store" is set to [not applicable] so the authentications will be based on trusted certs only. ISE will still perform groups/attributes lookup using the subject alternative name as user name if your authorization policy rules are using those identity stores.

Thanks hslai, that makes sense.

Correct me if I'm wrong:

Authentication Part: If user certificate is from trusted CA, the user gets authenticated and no ID Stores would be checked.

Authorization Part: Subject Alternative Name would be checked in the ID stores as per Authorization Policy.

hslai
Cisco Employee
Cisco Employee

Correct.

Is there any basic config example for certificate based authentication both for ISE and Client side?

hslai
Cisco Employee
Cisco Employee

ISE Training has links to various materials.


We have some GOLD labs via SalesConnect but these offerings are ending this Thursday.


BYOD -- shows using ISE BYOD to provision a certificate to an Apple iDevice using ISE internal CA

Integrating ISE with Active Directory -- shows using GPO in AD to provision certificates and authorize using AD.



Thanks hslai for your comments and suggestions.