cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
476
Views
0
Helpful
2
Replies

EAP-TLS question

jerome.gomez
Level 1
Level 1

Hi,

does anybody know if, by using EAP-TLS, it's possible to start network connection before login like with LEAP. I tryed it but the certificate seems to be personnal. Is it possible to associate this one to the computer only (with a generic store or user) ???

In fact i'd like my stations to be reachable even if nobody's logged onto.

Thanks for help

2 Replies 2

cdeeds
Level 1
Level 1

I don't believe you can use EAP-TLS for "generic" PC authentication since the credentials for authentication are based off of the certificate that the user must import into their local machine store along with their network logon credentials. With the certificate that the user(s) imports into their local machine store, the "Issued to:" field of the certificate must match the user's account name in the DB that ACS is using for this, whether it's an external DB such as Active Directory or whatever. So, you are correct in saying that the user certificate seems to be personal to the specified user.

Hope that helps.

Same way that i thinked

many thanks

Review Cisco Networking for a $25 gift card