cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3522
Views
10
Helpful
1
Replies

MacOS PEAP-MSCHAPv2 computer authentication

vsurresh
Level 1
Level 1

Hello. 

I know there's been plenty of topics regarding Windows based 802.1X computer authentication but none of them seem to provide an explanation for MacOS. 

I'm familiar with how 'user authentication' works on MacOS but struggling to understand the 'computer authentication' The requirement is to ONLY use 'computer authentication' with 802.1X so, if a user has a company issued/domain joined MacBook the access should be granted. 

With PEAP-MSCHAPv2 which computer credentials are exchanged between the client and ISE? The username would be the computer name (which exists in AD) but what about the password? My understanding is that PEAP requires username AND a password. 

At the moment the authentication works as expected but I'm struggling to understand the password MacBook sends out to ISE. 

Example: If the name of the computer is domain\EX1234 then ISE log shows this as the 'username'

 

Windows-10 - I understand that when a Windows based computer joins AD, a password is automatically created and being used with PEAP. 

Thank you.

 

1 Accepted Solution

Accepted Solutions

vsurresh
Level 1
Level 1

Never mind, I managed to figure out. I can see the password is saved in Active Directory. It seems MacOS behaves the same way as Windows. 

View solution in original post

1 Reply 1

vsurresh
Level 1
Level 1

Never mind, I managed to figure out. I can see the password is saved in Active Directory. It seems MacOS behaves the same way as Windows. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: