08-26-2017 08:06 PM
Hi Members,
When we have Certificate Authentication Profile setup and haven't setup Identity Sequence in Authentication Profile, which Identity Store would ISE look for attributes mentioned in CAP Policy?
Solved! Go to Solution.
08-27-2017 07:25 PM
The certificate attribute designated for the user identity is used as the subject/user to lookup for groups/attributes in identity stores as specified in the authorization policy rules. They can be any internal or external identity stores configured in ISE.
08-27-2017 07:25 PM
The certificate attribute designated for the user identity is used as the subject/user to lookup for groups/attributes in identity stores as specified in the authorization policy rules. They can be any internal or external identity stores configured in ISE.
08-29-2017 06:02 PM
What about the authentication part?
For Authentication, would it check the ID Store specified in Authorization rule?
08-29-2017 06:16 PM
It depends on Steps 3 ~ 5 of Add a Certificate Authentication Profile
In case that no identity store chosen in Step 3, then ISE uses those certificates designed for client authentication in Trusted Certificates only.
08-29-2017 06:25 PM
Thanks hslai.
Could you please have a look at the attached CAP Profile?
Would it be checking ID Store specified in Authorization Rule?
If yes, what happens during Authentication? How would the user get authenticated?
08-29-2017 06:36 PM
The "Identity Store" is set to [not applicable] so the authentications will be based on trusted certs only. ISE will still perform groups/attributes lookup using the subject alternative name as user name if your authorization policy rules are using those identity stores.
08-29-2017 06:41 PM
Thanks hslai, that makes sense.
Correct me if I'm wrong:
Authentication Part: If user certificate is from trusted CA, the user gets authenticated and no ID Stores would be checked.
Authorization Part: Subject Alternative Name would be checked in the ID stores as per Authorization Policy.
08-29-2017 06:43 PM
Correct.
08-29-2017 06:49 PM
Is there any basic config example for certificate based authentication both for ISE and Client side?
08-29-2017 07:17 PM
ISE Training has links to various materials.
We have some GOLD labs via SalesConnect but these offerings are ending this Thursday.
BYOD -- shows using ISE BYOD to provision a certificate to an Apple iDevice using ISE internal CA
Integrating ISE with Active Directory -- shows using GPO in AD to provision certificates and authorize using AD.
08-29-2017 08:12 PM
Thanks hslai for your comments and suggestions.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide