cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1196
Views
10
Helpful
2
Replies

EAP-TLS - Device vs User certificates

monolog99
Level 1
Level 1

Hi,

I have a Cisco ISE server authenticating our Wi-Fi users via EAP-TLS using the Local Computer / Machine certificate on the users PC. The users PC's also have Current User certificates installed as well.  I'm trying to use the user cert for authentication in order that I can then perform an AD lookup against the CN of that cert, which is the username.  However,  ISE is using the device certificate instead, where the CN of that cert is the PC name.

How do you tell ISE to use the User cert instead of the device/machine cert for EAP-TLS ?

Thanks,
Tim.

1 Accepted Solution

Accepted Solutions

@monolog99 you need to configure the supplicant on the windows computer to use "User or computer authentication"

Example: https://integratingit.wordpress.com/2019/07/13/configuring-windows-gpo-for-802-1x-authentication/

 

View solution in original post

2 Replies 2

@monolog99 you need to configure the supplicant on the windows computer to use "User or computer authentication"

Example: https://integratingit.wordpress.com/2019/07/13/configuring-windows-gpo-for-802-1x-authentication/

 

Many thanks Rob. Cheers.