cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
871
Views
0
Helpful
4
Replies

ISE ECC support for iOS

ppoggi
Cisco Employee
Cisco Employee

Hi team,

still in ISE 2.4 compatibility matrix it is said that in case of ECC certificate Apple iOS does not natively support ECC for EAP-TLS authentication. Anyone knows if this can be achieved using alternative methods, e.g. via a supplicant or 3rd party app?

Thanks,

Paolo

4 Replies 4

hslai
Cisco Employee
Cisco Employee

Nope. Apple iOS 10.x has not yet been supporting identity certificates with ECC keys for EAP-TLS.

ppoggi
Cisco Employee
Cisco Employee

Hi,

thanks for your reply.

If I'm not mistaken latest iOS release is 11.3.x.

Any known app that could overcome this limitation?

Regards,

Paolo

hslai
Cisco Employee
Cisco Employee

No. Apple iOS is using the native supplicant for DOT1X and that is supporting such currently.

hslai
Cisco Employee
Cisco Employee

It seems to work when I tried it again on my iOS 11.4 device. I used ISE internal CA with ECC P-521 and ISE certificate provisioning portal to generate key+certificate in .p12. Then, I used Apple Configurator 2 to create a new config profile, to import the identity cert and the PSN certificate, and to configure a WiFi with TLS with the ID certificate and trust the PSN certificate. I just emailed it to myself and opened it on my iOS device to import it as a profile.

Screen Shot 2018-06-15 at 8.15.59 PM.png

Thus, it would probably work using ISE BYOD as well. I will ask around or try that later.