03-09-2016 08:46 AM - edited 07-05-2021 04:44 AM
We've got a wireless network set up already and we're getting a Cisco ISE for this project. We're investigating deploying two factor authentication, with the two factors being: Domain Username/Password and a Certificate.
Is the only way to do two factor authentication like this with EAP-Chaining?
Will EAP-Chaining work on Android and Apple IOS devices?
03-09-2016 03:31 PM
Have you considered using a USB secure certificate token store instead? An example is something like this:
http://www.safenet-inc.com/data-protection/password-protection-applications/?aldn-true
Basically you issue a certificate, and it is stored on the USB token. You give this to the user along with (usually) a PIN.
The user plugs the token into their machine, and they get asked for the PIN. This unlocks the certificate store, and it now shows up as a normal certificate store in windows.
Being a normal certificate store you can use the certificate for WiFi authentication, VPN authentication, Email encryption, etc.
You may be able to use other methods aside from a PIN. I have only seen it used with a PIN.
03-09-2016 03:32 PM
Actually this is a better link.
http://www.safenet-inc.com/multi-factor-authentication/authenticators/pki-usb-authentication/
03-09-2016 05:55 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide