04-29-2003 01:23 AM - edited 07-04-2021 08:40 AM
Hi,
does anybody know if, by using EAP-TLS, it's possible to start network connection before login like with LEAP. I tryed it but the certificate seems to be personnal. Is it possible to associate this one to the computer only (with a generic store or user) ???
In fact i'd like my stations to be reachable even if nobody's logged onto.
Thanks for help
04-30-2003 12:59 PM
I don't believe you can use EAP-TLS for "generic" PC authentication since the credentials for authentication are based off of the certificate that the user must import into their local machine store along with their network logon credentials. With the certificate that the user(s) imports into their local machine store, the "Issued to:" field of the certificate must match the user's account name in the DB that ACS is using for this, whether it's an external DB such as Active Directory or whatever. So, you are correct in saying that the user certificate seems to be personal to the specified user.
Hope that helps.
05-05-2003 12:19 AM
Same way that i thinked
many thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide