<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XIQ: using 802.1X-TLS in a enterprise SSID with a certificate stored in cloud (XIQ) in Hero Product Suggestions</title>
    <link>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58350#M15</link>
    <description>&lt;P&gt;In XIQ we have the possibility to use the cloud authentication service where accounts stored in a DB in the XIQ. Why not using a central cloud stored certificate from a private or public PKI to authenticate users/devices with enterprise SSIDs ?&lt;/P&gt;&lt;P&gt;Currently you will need a external radius server only for checking the certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 23:35:00 GMT</pubDate>
    <dc:creator>Volker_Kull</dc:creator>
    <dc:date>2020-11-04T23:35:00Z</dc:date>
    <item>
      <title>XIQ: using 802.1X-TLS in a enterprise SSID with a certificate stored in cloud (XIQ)</title>
      <link>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58350#M15</link>
      <description>&lt;P&gt;In XIQ we have the possibility to use the cloud authentication service where accounts stored in a DB in the XIQ. Why not using a central cloud stored certificate from a private or public PKI to authenticate users/devices with enterprise SSIDs ?&lt;/P&gt;&lt;P&gt;Currently you will need a external radius server only for checking the certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 23:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58350#M15</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2020-11-04T23:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: XIQ: using 802.1X-TLS in a enterprise SSID with a certificate stored in cloud (XIQ)</title>
      <link>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58351#M16</link>
      <description>&lt;P&gt;Hi Volker,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but what prevents you from using cloud-based RADIUS server? Azure, for instance, provides such option via Azure AD directory services and/or NPS VM in their cloud.&lt;/P&gt;&lt;P&gt;XIQ is not an Identity Provider/catalog itself. Yes, it provides some identity storage capabilities for simple cases, but there is no intention to turn it into full-fledged cloud IdP.&lt;/P&gt;&lt;P&gt;So I would suggest using integration capabilities of our Cloud solutions to “marry” them with external IdPs, which can be either on-prem or cloud-based.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 17:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58351#M16</guid>
      <dc:creator>AlexN</dc:creator>
      <dc:date>2020-12-02T17:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: XIQ: using 802.1X-TLS in a enterprise SSID with a certificate stored in cloud (XIQ)</title>
      <link>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58352#M17</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;With XiQ we can use several internal (cloud based) authentication sources (guest users, PPSK accounts and users in a XIQ cloud DB which we can match to a 802.1X-PEAP profile). Making life easier and more secure for the customers we want to use this existing internal 802.1X authentication feature to expand this for 802.1X-TLS authentication and use a certificate stored in XIQ for authenticating devices. The goal is to limit the external interfaces like Radius for a simple TLS authentication.&lt;/P&gt;&lt;P&gt;With a cloud only strategy at the customer need to use a cloud based RaaS but with unsecure Radius protocol. This is not secure and difficult to manage: which AP/switch will communicate with RaaS, redundancy, content of response,…&lt;/P&gt;&lt;P&gt;With that this will be a unique selling point.&lt;/P&gt;&lt;P&gt;br Volker&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 18:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58352#M17</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2020-12-02T18:02:00Z</dc:date>
    </item>
    <item>
      <title>RE: XIQ: using 802.1X-TLS in a enterprise SSID with a certificate stored in cloud (XIQ)</title>
      <link>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58353#M18</link>
      <description>&lt;P&gt;That one is really good, I’m only thinking where to stick it in - XIQ or Extreme Guest Essentials ? But that’s rhetoric question, let me figure it out inside..&lt;/P&gt;&lt;P&gt;BTW RaaS based on RadSec isn’t really insecure, as TLS authentication there is mutual.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2020 00:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-product-suggestions/xiq-using-802-1x-tls-in-a-enterprise-ssid-with-a-certificate/m-p/58353#M18</guid>
      <dc:creator>AlexN</dc:creator>
      <dc:date>2020-12-05T00:51:00Z</dc:date>
    </item>
  </channel>
</rss>

