Windows client authenticating fine but the for EAP-TLS/Machine authentication but the Macintosh client does not. Background: The issue is due to the Windows client prepends a "host/" in front of the name on the certificate and the Macintosh client does not.
Macintosh client in failed authentication log on ACS.: 02/16/2011 07:28:53 Authen failed xyz.domain.com Default Group External user not found
Windows Client: 02/17/2011 07:29:52 Authen OK host/xyz.domain.com Network-Switch. How to configure MAC OS to work using EAP TLS. To make it work Cert should have,
The CN as host/computername@domainname The SAN as DNS=computername@domainname
The two names have to be different as shown above. To make this work we need the CN=host/ and the SAN name without the host/.
If we just used the existing ‘machine’ template in the Microsoft CA server, and changed the CN name we will not get any SAN name at all.
--> By default, a CA that is configured on a Windows Server 2003-based computer does not issue certificates that contain the SAN extension. If SAN entries are included in the certificate request, these entries are omitted from the issued certificate.
To get the SAN attribute in the certificate, on the Cert we need to run the following commands at a command prompt on the server that runs the Certification Authority service.
Press ENTER after each command.
certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2 net stop certsvc net start certsvc”
--> Then generate and import a certificate that had the correct names. --> Set up the ACS to use the SAN name as for the comparison and the “outer identity” as the username.
I am taking this exam tomorrow. There hasn't been much study material since its release and I am not willing to pay $1000 for the Cisco training. The exam cost is already $400. I am taking this to renew my CCNA and Cyber Ops Associate.&n...
Hi Team,I'm having some issue that I'm almost sure that I've succeeded with it in the past. We have a device type "x", and we want the following thing : 1. Admins user [an AD group] - will have privilege 152. Internal User "user" - will be...
Hi Guys,I have deployed and actively running ISE (SNS-3615-k9).Today I have monitored two LEDs blinking in amber color. One is "FAN" icon and other one is "S" icon. Both LEDs' are blinking continuously. What are the possible reasons for them. (Please...
Only Error Message I receive is "Login Error".My Logindata is correct and several of my colleagues have the same issue.How do we fix it?Message history below.9:30:46 PM Contacting unibn-vpn.9:30:52 PM User credentials entered.9:30:55 PM User credenti...