05-24-2019 03:45 AM - edited 05-24-2019 03:46 AM
Hi,
I have a customer who doesn’t have on-prem user directory and CA. They are very much interested in ISE. However, the challenge is to have dot1x authentication.
Can we use certificate based authentication for dot1x and configure ISE to act as a CA server and issue certificates to endpoints? I know that ISE issues the certs for BYOD only. But I think we can use certificate provisioning portal to manually download and install the certs to endpoints. So in this case, when the certificates are issued by ISE and dot1x is triggered, how can ISE validate the endpoint’s certificate?
P.S. Cucstomer doesn’t want to create local user database in ISE.
Thanks,
Rakesh Kumar
Solved! Go to Solution.
05-24-2019 10:06 AM
05-24-2019 04:51 AM
05-24-2019 05:01 AM
Hi Jason,
I have been posting a lot of questions these days and all are about the same customer. They have Jumpcloud, which is directory as a service in cloud. I checked with some folks and found that Jumpcloud is not supported/validated. Apart from that, they have G-Suite and JAMF for MAC users.
So if we have admin downloading all the certificates for all the endpoints, the distribution can be done using any other medium. Let's assume that is not a problem. Consider endpoints are having certificates then how ISE would validate them without having AD/LDAP/Local database?
05-24-2019 05:19 AM
05-24-2019 06:04 AM
05-24-2019 05:22 AM
05-24-2019 09:47 AM
Jason, Mike,
What you guys are saying that makes sense. So how do we configure this? What's the recommended configuration in ISE to validate endpoint's certificates issued by ISE?
05-24-2019 10:06 AM
05-24-2019 10:31 AM - edited 05-24-2019 10:54 AM
So if I understood correctly then step 2 is doing certificate validation and authorizing users?
If they don't have certs then cert provisioning will be done by step 3 and 4? But how we can have different authorization policies for different set of users?
05-24-2019 10:45 AM
05-24-2019 11:25 AM
Thanks Jason and Mike, that was helpful. Will try with different set of conditions.
05-24-2019 11:31 AM
05-24-2019 11:32 AM
05-24-2019 11:43 AM
Yes Jason, you are right. We won't be able to authenticate users if we do not have a user directory (AD/Local). Using certificates also, ISE will be just able to validate the certs, not users. However, if customer agrees to this then we can have some sort of control on whether someone is having valid credentials. And having some certificate attributes in authorization conditions, ISE can apply different authorization policies to different set of users.
05-24-2019 12:01 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide