09-20-2019 05:48 AM
We have a wired authentication issue and I can't find a solution. The problem is this: we use user or computer certificates issued by Windows domain CA for authentication and it works fine. The certificates are enrolled automatically through GPO when a PC joins the domain or a user logon to Windows with a domain account. The issue happens on the first time when a PC joins the domain or a user logs on to Windows the first time. This is when the certificates are not loaded yet. It seems like a "chicken or egg first" type of problem. Just wonder if anyone encountered similar issue and how to solve it.
Thanks
Richard Poon
09-20-2019 07:05 AM
09-20-2019 08:06 AM
Machine auth only policy won't work, since it's by design that only user certificate will be presented once the PC is user logged in. Then the port will become unauthenticated within a minute because machine certificate is not visible to the switch port.
09-29-2019 08:33 AM
Damien Miller's suggestion in allowing it to fall-back to MAB should be a valid solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide