12-26-2019 08:54 PM
Hi all,
I am using ise 2.4 with windows AD for my environment's 802.1x
I am using both user and machine cert authentication. I have also enabled the option "always perform binary comparison" for both my user and machine cert authentication profile.
With reference to the following taken from (https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html), how does ISE retrieve the cert from my AD?
"The certificate authentication profile determines the field where the username is taken from in order to lookup the user in Active Directory to be used for retrieving certificates, for example, Subject Alternative Name (SAN) or Common Name. After Cisco ISE retrieves the certificate, it performs a binary comparison of this certificate with the client certificate. When multiple certificates are received, Cisco ISE compares the certificates to check for one that matches. When a match is found, the user or machine authentication is passed."
Solved! Go to Solution.
12-26-2019 09:38 PM
12-26-2019 09:38 PM
12-26-2019 11:59 PM
Hi Francesco,
Thank you very much for your advise. Indeed my user AD objects has "published certificates" tab but my computer objects doesn't. And the binary comparison option is enabled for my machine authentication profile which my machines is able to perform successfully. Any reason why?
12-29-2019 05:24 PM
10-23-2023 02:18 AM
Hello Francesco,
I have same problem too. Would you please kindly advise which attribute is used for ldap fetching in AD ? Thank you.
02-04-2023 09:25 AM
I appreciate your advice very lot. Although my computer objects lack the "published certificates" tab, my user AD objects do. Additionally, the binary comparison option is enabled for my machine authentication profile, and my machines can successfully complete it. Can you explain why this is helpful?
Regards: binary options signals free
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide