<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XIQ SE and Windows 11 Authentication EAP TLS in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/120826#M12864</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;EAP-TLS is supported in XIQ-Site Engine, including the version you’re running. The limitation is usually in the NAC configuration, not the platform version. To use EAP-TLS you’ll need a proper certificate chain: a server certificate on the NAC/RADIUS engine and the corresponding root or intermediate CA uploaded into the trusted authorities list so the engine can validate client certificates.&lt;/P&gt;&lt;P&gt;On the Windows side, each client needs a user or computer certificate issued by the same CA, and Windows 11 will authenticate cleanly with EAP-TLS once those certificates and profiles are in place. Your existing LDAP-based PEAP/MSCHAPv2 setup won’t be used anymore because TLS relies on certificates instead of passwords.&lt;/P&gt;&lt;P&gt;Implementation is straightforward: generate a CSR on the NAC engine, get it signed by your CA, import the server certificate and root CA, switch the authentication method in your access policies to &lt;A href="https://spotipremiums.com/" target="_self"&gt;Spotify APK Premium&lt;/A&gt;, and then enforce the configuration to your engines. After that, deploy certificates and an 802.1X profile to Windows 11 via GPO or Intune.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Sun, 23 Nov 2025 06:58:15 GMT</pubDate>
    <dc:creator>jerrygen</dc:creator>
    <dc:date>2025-11-23T06:58:15Z</dc:date>
    <item>
      <title>XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118203#M12621</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;We have upgraded from Win 10 to Win 11 and are currently using EAP PEAP as the 802.1x authentication method.&amp;nbsp; I was told this would no longer work with Win 11 and we would need to implement EAP TLS.&amp;nbsp; I understand EAP TLS is not available for the version of XIQ SE we have -&amp;nbsp;&lt;SPAN&gt;23.4.12.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, I believe later version of XIQ SE support EAP TLS.&amp;nbsp; If this is not the case please let me know. Could anyone let me know which minimum version of XIQ SE supports EAP TLS for XIQ SE and will I need a root certificate to be installed on XIQ SE and the NAC devices?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there a guide or similar I could use to Implement EAP TLS?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Currently, we use the built in 802.1x authentication via a LDAP server.&amp;nbsp; This I believe supports&amp;nbsp;MsCHAP, PEAP and EAP-MsCHAPV2 only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Many Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 11:36:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118203#M12621</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-13T11:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118207#M12623</link>
      <description>&lt;P&gt;Hi Asifi,&lt;/P&gt;&lt;P&gt;PEAP is available in Windows 11:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zdenk_Pala_0-1741868761408.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8772i537A0BDDCD276736/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zdenk_Pala_0-1741868761408.png" alt="Zdenk_Pala_0-1741868761408.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS is available since the beginning of XIQ-SE. Documentation:&amp;nbsp;&lt;A href="https://emc.extremenetworks.com/content/search.htm?q=eap-tls" target="_blank" rel="noopener"&gt;https://emc.extremenetworks.com/content/search.htm?q=eap-tls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Anyway, I heavily recommend upgrading to recent version of XIQ-SE because of new features and security patches.&lt;/P&gt;&lt;P&gt;Sincerely yours&lt;/P&gt;&lt;P&gt;Zdenek&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 12:27:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118207#M12623</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2025-03-13T12:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118208#M12624</link>
      <description>&lt;P&gt;Hi Asifi,&lt;/P&gt;&lt;P&gt;Any version of XIQ-SE supports EAP-TLS.&lt;/P&gt;&lt;P&gt;If you want EAP-PEAP to be still supported in Windows 11 clients, you will probably need to disable Credential Guard feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;These links might be useful:&lt;/P&gt;&lt;P&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000100238&amp;amp;q=windows%2011%20802%201x" target="_blank" rel="noopener"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000100238&amp;amp;q=windows%2011%20802%201x&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However, using EAP-TLS is a way better than EAP-PEAP in terms of security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REGARDS, Robert&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 12:30:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118208#M12624</guid>
      <dc:creator>Robert_Zdzieblo</dc:creator>
      <dc:date>2025-03-13T12:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118210#M12626</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/30612"&gt;@Robert_Zdzieblo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/25315"&gt;@Zdeněk_Pala&lt;/a&gt;&amp;nbsp;- thanks both, that is interesting.&amp;nbsp; I will upgrade&amp;nbsp; - which version do you recommend from my current version?&amp;nbsp; I know somewhere down the line the upgrade involves a new VM creation and backup/restore of the database.&amp;nbsp; Which version can I go to without creating a new VM?&lt;/P&gt;&lt;P&gt;Secondly, if I go with EAP TLS - I need a Root certificate on XIQ SE and the NAC's?&lt;/P&gt;&lt;P&gt;Any documentation for this?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 12:55:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118210#M12626</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-13T12:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118211#M12627</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If you are working with AD environment, then I would recommend deploying at least one NPS server (o even two for redundancy) to handle RADIUS authentication with NAC and keep LDAP integration just for checking user attributes for applying correct network authorization.&lt;/P&gt;&lt;P&gt;NTLM protocol used by NAC for local RADIUS termination is somehow deprecated by Microsoft (&lt;A href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features)" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 12:55:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118211#M12627</guid>
      <dc:creator>Bartek</dc:creator>
      <dc:date>2025-03-13T12:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118212#M12628</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/17121"&gt;@Bartek&lt;/a&gt;&amp;nbsp;- we use an NPS to authenticate our Extreme AP users.&amp;nbsp; However, in this case I am talking about our end user devices so PC's/tablets/laptops etc.&amp;nbsp; Are you suggesting using NPS for the end devices too?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 13:10:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118212#M12628</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-13T13:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118213#M12629</link>
      <description>&lt;P&gt;Asifi,&lt;/P&gt;&lt;P&gt;I think you can't avoid migration during XIQ-SE upgrade to current version. There is stepped upgrade path from your version and during upgrade to 24.7 there is migration required between 2 VMs - all info can be found in XIQ-SE Release Notes.&lt;/P&gt;&lt;P&gt;Regarding the certificate - you'll need your CA signed certificates on NAC gateways, but not necessarily on XIQ-SE itself.&lt;/P&gt;&lt;P&gt;REGARDS, Robert&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 13:24:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118213#M12629</guid>
      <dc:creator>Robert_Zdzieblo</dc:creator>
      <dc:date>2025-03-13T13:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118214#M12630</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/30612"&gt;@Robert_Zdzieblo&lt;/a&gt;&amp;nbsp;- thank you for confirming.&amp;nbsp; Can I update the existing authentication to use EP TLS or will this require new rules?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 13:34:25 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118214#M12630</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-13T13:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118218#M12631</link>
      <description>&lt;P&gt;Hi All, will I need a pfx or cer certificate for the NAC's?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 15:16:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118218#M12631</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-13T15:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118219#M12632</link>
      <description>&lt;P&gt;PEAP-MSCAP is still supported with Windows 11. More and more customer moving to EntraID replacing the classical Active Directory we know since many years. Using EAP-TLS is a good alternative if you know how to deal with client certificates in regards auto enrollment and live cycle management. Just make sure the client have certificate with "enhance key usage" = "Client Authentication" and select the certificates in the Windows 11 plus the corresponding root CA certificate to be able to validate the incoming Radius server certificate like you should have already with PEAP-xxx.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 15:23:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118219#M12632</guid>
      <dc:creator>Markus_Nikulski</dc:creator>
      <dc:date>2025-03-13T15:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118220#M12633</link>
      <description>&lt;P&gt;the pfx extension indicate is a PLCS12 formatted data. Yes it can be used to deploy the certificate for the Radius server.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 15:25:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118220#M12633</guid>
      <dc:creator>Markus_Nikulski</dc:creator>
      <dc:date>2025-03-13T15:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118221#M12634</link>
      <description>&lt;P&gt;we don't promote the&amp;nbsp;&lt;SPAN&gt;NPS&amp;nbsp;servie because we have XIQ-SE NAC scaling much better and have a enterprise great NAC solution.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 15:26:53 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118221#M12634</guid>
      <dc:creator>Markus_Nikulski</dc:creator>
      <dc:date>2025-03-13T15:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118228#M12635</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/43066"&gt;@Markus_Nikulski&lt;/a&gt;&amp;nbsp;- Thanks Marcus, we use an LDAP server for user and machine authentication.&amp;nbsp; PFX still ok?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 15:56:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118228#M12635</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-13T15:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118229#M12636</link>
      <description>&lt;P&gt;yes, it will work for group membership lookup. The user authentication is part of the offline certificate validation.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 16:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118229#M12636</guid>
      <dc:creator>Markus_Nikulski</dc:creator>
      <dc:date>2025-03-13T16:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118233#M12637</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/43066"&gt;@Markus_Nikulski&lt;/a&gt;&amp;nbsp;I'm not promoting NPS as NAC but as RADIUS server for Extreme Access Control (so Extreme NAC is used as RADIUS Proxy). IMO NTLM integration with AD environment is somehow not as reliable as RADIUS-based integration&lt;/P&gt;&lt;P&gt;SWITCH/AP &amp;lt;---&amp;gt; Extreme Control &amp;lt;----&amp;gt; NPS (RADIUS) + AD (LDAP)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 19:50:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118233#M12637</guid>
      <dc:creator>Bartek</dc:creator>
      <dc:date>2025-03-13T19:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118234#M12638</link>
      <description>&lt;P&gt;I'm suggesting integrating Extreme Control with on-prem AD environment using RADIUS protocol for user authentication (it's called RADIUS Proxy mode) and LDAP for checking user access permissions:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;SWITCH/AP &amp;lt;---&amp;gt; Extreme Control &amp;lt;----&amp;gt; NPS (RADIUS) + AD (LDAP)&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Mar 2025 19:59:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118234#M12638</guid>
      <dc:creator>Bartek</dc:creator>
      <dc:date>2025-03-13T19:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118247#M12641</link>
      <description>&lt;P&gt;As mentioned by others, any XIQ-SE/NAC version support EAP-TLS.&lt;BR /&gt;You'll need server certificate issued by your CA for the NAC appliance/VM but not for XIQ-SE.&lt;BR /&gt;&lt;BR /&gt;Only NAC appliance are RADIUS Server and will use server certificate to be validated by your Windows 11 devices.&lt;BR /&gt;&lt;BR /&gt;Even if Windows 11 still support PEAP (with Credential Guard disabled), never know if it'll be the case tomorrow because PEAP is deprecated because of security issues.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 12:47:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118247#M12641</guid>
      <dc:creator>SebBinet</dc:creator>
      <dc:date>2025-03-14T12:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118250#M12642</link>
      <description>&lt;P&gt;Any version of XIQ-SE/NAC supports EAP-TLS, as others have stated.&amp;nbsp;&lt;A href="https://thespotifypremium.net/" target="_self"&gt;APK Spotify Premium&lt;/A&gt;&lt;BR /&gt;Your CA's server certificate is required for the NAC appliance or virtual machine, but not for the XIQ-SE.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Only NAC appliances are RADIUS servers, and your Windows 11 devices will validate them using the server certificate.&lt;/P&gt;&lt;P&gt;PEAP is deprecated due to security concerns, thus even if Windows 11 currently supports it (with Credential Guard turned down), you never know if it will be the case tomorrow.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Mar 2025 05:51:25 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118250#M12642</guid>
      <dc:creator>nick533</dc:creator>
      <dc:date>2025-03-15T05:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118268#M12645</link>
      <description>&lt;P&gt;Thanks everyone - lots to ponder and think about.&lt;/P&gt;&lt;P&gt;My last question - we have a wildcard certificate already in use and verified by a CA.&amp;nbsp; Can we use this as the device cert on the NAC's as this already chains back to out PKI root without having to raise a new CSR and getting this verified by a CA.&lt;/P&gt;&lt;P&gt;Many thanks everyone.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 15:18:54 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118268#M12645</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-03-17T15:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: XIQ SE and Windows 11 Authentication EAP TLS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118277#M12649</link>
      <description>&lt;P&gt;We do not permit / advise the use of a wildcard certificate for the RADIUS server certificate for backwards compatibility with clients and 802.1x supplicant configurations that simply do not support it.&lt;/P&gt;&lt;P&gt;A RADIUS server cert w/ multiple SANs (FQDNs) is recommended.&lt;/P&gt;&lt;P&gt;Wildcard certificate is compatible with Captive Portal/Web use purposes.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 12:34:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xiq-se-and-windows-11-authentication-eap-tls/m-p/118277#M12649</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2025-03-18T12:34:05Z</dc:date>
    </item>
  </channel>
</rss>

