cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3181
Views
5
Helpful
6
Replies

ISE integrated with AD, if disable TLS1.0 on ISE , won't affect the communication, right?

Herman2018
Level 3
Level 3

Hi , ISE is integrated with AD and used for authentication users and device access admin, normally it use TLS 1.2 for the communication between ISE2.4 and AD 2016, right? anyone can please advise, thanks.

1 Accepted Solution

Accepted Solutions

Hi, no it should not have a problem

View solution in original post

6 Replies 6

Hi, no it should not have a problem

Thanks @Mohammed al Baqari . I also don't think it will be an issue, just try to get advice from expert. 

Good :) Just remember to rate useful posts

You should be very cautious about disabling it in production without prior testing. I had a customer disable TLS 1.0 support and it immediately broke EAP-TLS machine authentication used by all of their clients.

They immediately re-enabled it to regain connectivity so we're not sure whether they were still using TLS 1.0 for their CRL or something else that was causing a problem. You should test this in a non-production environment that mirrors your production environment first if possible or at least perform extensive testing after disabling it and be prepared to rollback the change.

Thanks @Greg Gibbs . Can you advise when your customer encountered the issue? For recently mobile devices all can support TLS1.2, the server also. 

As I said, it happened immediately after disabling TLS 1.0 in ISE. The next Windows PC that needed to authenticate using EAP-TLS failed.

If you disable TLS 1.0, you should do it in a change window and be sure to test any features you are using that are indicated as affected in the information bubble next to this setting in ISE (EAP, CRL, TCP Syslog, REST API, etc).