<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Using TLS Certificate fields for authentication mapping in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34683#M1365</link>
    <description>Hi Stephan.&lt;BR /&gt;
&lt;BR /&gt;
the decision to proxy or not can be made based on Location (Switch, Port, SSID, AP, Zone), based on username (pattern or group membership, in case of certificates the name is CN), based on authentication type.&lt;BR /&gt;
&lt;BR /&gt;
I suggest to terminate EAP-TLS locally and add more CA and more CRL to your configuration. The Access Control Engine can authorize based on more CA.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
&lt;BR /&gt;
Z.</description>
    <pubDate>Tue, 12 Jun 2018 10:29:00 GMT</pubDate>
    <dc:creator>Zdeněk_Pala</dc:creator>
    <dc:date>2018-06-12T10:29:00Z</dc:date>
    <item>
      <title>Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34680#M1362</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;can I use TLS certificate fields like "TLS-Cert-Issuer" or "TLS-Cert-Common-Name" (or other fields mentioned here: &lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000064090" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000064090&lt;/A&gt;) to do the authentication mapping in the NAC AAA configuration to e. g. switch between local authentication or proxy radius if I use 802.1x?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="d4d8ae978da84b7b950785e8ca94cd72_RackMultipart20180608-114138-1wldydo-AuthMapping_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/202iB14C3F5658CEA1BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="d4d8ae978da84b7b950785e8ca94cd72_RackMultipart20180608-114138-1wldydo-AuthMapping_inline.jpg" alt="d4d8ae978da84b7b950785e8ca94cd72_RackMultipart20180608-114138-1wldydo-AuthMapping_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If yes, how can I do set? What do I have to enter in the fields (User/MAC/Host)?&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Stephan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jun 2018 03:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34680#M1362</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-06-09T03:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34681#M1363</link>
      <description>Stephan, are you looking to use a cert field for making a decision if to proxy the request to another server or auth locally? or are you looking to perform the auth by ExtremeControl server but use a cert field to make an authorization decision as what network service to assign?</description>
      <pubDate>Mon, 11 Jun 2018 11:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34681#M1363</guid>
      <dc:creator>Shmulik</dc:creator>
      <dc:date>2018-06-11T11:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34682#M1364</link>
      <description>Hello Shumlik,&lt;BR /&gt;
&lt;BR /&gt;
I want to make a decision if to proxy or do a locally auth.&lt;BR /&gt;
&lt;BR /&gt;
Best regards&lt;BR /&gt;
Stephan&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Jun 2018 11:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34682#M1364</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-06-11T11:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34683#M1365</link>
      <description>Hi Stephan.&lt;BR /&gt;
&lt;BR /&gt;
the decision to proxy or not can be made based on Location (Switch, Port, SSID, AP, Zone), based on username (pattern or group membership, in case of certificates the name is CN), based on authentication type.&lt;BR /&gt;
&lt;BR /&gt;
I suggest to terminate EAP-TLS locally and add more CA and more CRL to your configuration. The Access Control Engine can authorize based on more CA.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
&lt;BR /&gt;
Z.</description>
      <pubDate>Tue, 12 Jun 2018 10:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34683#M1365</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-06-12T10:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34684#M1366</link>
      <description>Thank you Pala,&lt;BR /&gt;
&lt;BR /&gt;
can I use only parts of the certificate CN, too? Like "host/*" in an user name.&lt;BR /&gt;
&lt;BR /&gt;
Best regards&lt;BR /&gt;
Stephan&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jun 2018 10:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34684#M1366</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-06-12T10:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34685#M1367</link>
      <description>Yes you can use wildcard to check the username. Username is the CN.</description>
      <pubDate>Tue, 12 Jun 2018 10:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34685#M1367</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-06-12T10:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34686#M1368</link>
      <description>Thank  you Pala.</description>
      <pubDate>Tue, 12 Jun 2018 10:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34686#M1368</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-06-12T10:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34687#M1369</link>
      <description>&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="93cf1bfb5b99431dbfea921bd0599643_RackMultipart20180620-23854-1tjbehy-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1465i0DE8E71738222339/image-size/large?v=v2&amp;amp;px=999" role="button" title="93cf1bfb5b99431dbfea921bd0599643_RackMultipart20180620-23854-1tjbehy-image_inline.png" alt="93cf1bfb5b99431dbfea921bd0599643_RackMultipart20180620-23854-1tjbehy-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I can only show a screenshot in OneView.&lt;BR /&gt;
&lt;BR /&gt;
You can make a User Group and Change it to RADIUS User Group, then you can rely on TLS Attributes.&lt;BR /&gt;
We did it with TLS-Client-Cert-Common-Name, but others should also be possible.&lt;BR /&gt;
&lt;BR /&gt;
Does anyone has a list of which attributes are possible?&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Jun 2018 20:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34687#M1369</guid>
      <dc:creator>AntonS</dc:creator>
      <dc:date>2018-06-20T20:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using TLS Certificate fields for authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34688#M1370</link>
      <description>Hello Anton,&lt;BR /&gt;
&lt;BR /&gt;
you will see the attributes in the KB article following the link in my first text above.&lt;BR /&gt;
&lt;BR /&gt;
Best regards&lt;BR /&gt;
Stephan&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Jun 2018 20:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/using-tls-certificate-fields-for-authentication-mapping/m-p/34688#M1370</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-06-20T20:31:00Z</dc:date>
    </item>
  </channel>
</rss>

