Windows client authenticating fine but the for EAP-TLS/Machine authentication but the Macintosh client does not. Background: The issue is due to the Windows client prepends a "host/" in front of the name on the certificate and the Macintosh client does not.
Macintosh client in failed authentication log on ACS.: 02/16/2011 07:28:53 Authen failed xyz.domain.com Default Group External user not found
Windows Client: 02/17/2011 07:29:52 Authen OK host/xyz.domain.com Network-Switch. How to configure MAC OS to work using EAP TLS. To make it work Cert should have,
The CN as host/computername@domainname The SAN as DNS=computername@domainname
The two names have to be different as shown above. To make this work we need the CN=host/ and the SAN name without the host/.
If we just used the existing ‘machine’ template in the Microsoft CA server, and changed the CN name we will not get any SAN name at all.
--> By default, a CA that is configured on a Windows Server 2003-based computer does not issue certificates that contain the SAN extension. If SAN entries are included in the certificate request, these entries are omitted from the issued certificate.
To get the SAN attribute in the certificate, on the Cert we need to run the following commands at a command prompt on the server that runs the Certification Authority service.
Press ENTER after each command.
certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2 net stop certsvc net start certsvc”
--> Then generate and import a certificate that had the correct names. --> Set up the ACS to use the SAN name as for the comparison and the “outer identity” as the username.
Hi Experts,I got these commands from Cisco documents to deploy AnyConnect silently to a bunch of PC as part of migration project. This is make sure that there is really no user interaction when this AnyConnect push is happening.Commands: msiexec /pac...
Hi all,I would like to ask about 802.1x.It is very simple question for you but i can't understand easily.i would like to deploy 802.1x wired authentication. i am applied static vlan and ACL rule is already applied on the switches.Can i deploy 802.1x ...
Hi guys,I need help with redirection for ISE posturing.When I manually paste the redirection URL to my browser everything works fine but somehow, I can't get automatic redirection to work.I have attached everything that I think may be helpful for you to a...