cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2052
Views
0
Helpful
1
Replies

EAP Chaining with EAP-TLS

Daryl Clark
Level 1
Level 1

Hello...re-deploying 802.1x within a network with high security requirements. Fully functional PKI deployment is already out that issues both user and machine certificates. Also using Cisco NAM 4.5 as supplicant and ISE 2.2 as RADIUS server.

 

Setting up EAP-TLS for machine authentication is very easy to do. User authentication not so much. When setting up the new profile in Network Access Manager and I get to the "Credentials" tab of the network setup, I am prompted to "Use Single Sign On Credentials" or "Prompt for Credentials". We do not use Smart Cards so I cannot use the SSO Creds but I want to provide my end uses with the SSO experience and not have them have to select a certificate to use for authentication.

 

Capture.PNG

 

Any help would be appreciated.

1 Accepted Solution

Accepted Solutions

Hi Daryl,


Under User Credentials select - Prompt for Credentials > Remember while user is logged on. Then under Certificate sources ensure "Smart card or OS certificates" is selected. I've used this configuration and machine/user authentication is transparent to the user.

 

HTH

View solution in original post

1 Reply 1

Hi Daryl,


Under User Credentials select - Prompt for Credentials > Remember while user is logged on. Then under Certificate sources ensure "Smart card or OS certificates" is selected. I've used this configuration and machine/user authentication is transparent to the user.

 

HTH