08-04-2020 02:28 AM
Hi , ISE is integrated with AD and used for authentication users and device access admin, normally it use TLS 1.2 for the communication between ISE2.4 and AD 2016, right? anyone can please advise, thanks.
Solved! Go to Solution.
08-04-2020 03:10 AM
08-04-2020 03:10 AM
08-06-2020 12:13 AM
Thanks @Mohammed al Baqari . I also don't think it will be an issue, just try to get advice from expert.
08-06-2020 12:55 AM
08-06-2020 01:03 AM
You should be very cautious about disabling it in production without prior testing. I had a customer disable TLS 1.0 support and it immediately broke EAP-TLS machine authentication used by all of their clients.
They immediately re-enabled it to regain connectivity so we're not sure whether they were still using TLS 1.0 for their CRL or something else that was causing a problem. You should test this in a non-production environment that mirrors your production environment first if possible or at least perform extensive testing after disabling it and be prepared to rollback the change.
08-06-2020 01:56 AM
Thanks @Greg Gibbs . Can you advise when your customer encountered the issue? For recently mobile devices all can support TLS1.2, the server also.
08-06-2020 04:02 PM
As I said, it happened immediately after disabling TLS 1.0 in ISE. The next Windows PC that needed to authenticate using EAP-TLS failed.
If you disable TLS 1.0, you should do it in a change window and be sure to test any features you are using that are indicated as affected in the information bubble next to this setting in ISE (EAP, CRL, TCP Syslog, REST API, etc).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide