<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC: flexible configuration of Trusted Root Certificates with LDAP-CRL or HTTP-CRL in Hero Product Suggestions</title>
    <link>https://community.extremenetworks.com/t5/hero-product-suggestions/nac-flexible-configuration-of-trusted-root-certificates-with/m-p/58420#M31</link>
    <description>&lt;P&gt;Today several different Trusted Root Certificates can be used in NAC (Control). With using of CRLs there are some restrictions limiting the use of certificates:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;only HTTP-CRLs are supported - default Active-Directory CRL is via LDAP&lt;/LI&gt;	&lt;LI&gt;if one of the PKIs behind a root certificate does not support CRL you have to disable CRL checking for all certificates&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What we need:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;flexible configuration of certificate path (PKI, protocol, CRL) individually for every single certificate&lt;/LI&gt;	&lt;LI&gt;adding LDAP CRL checking function&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
    <pubDate>Wed, 11 Nov 2020 15:27:00 GMT</pubDate>
    <dc:creator>Volker_Kull</dc:creator>
    <dc:date>2020-11-11T15:27:00Z</dc:date>
    <item>
      <title>NAC: flexible configuration of Trusted Root Certificates with LDAP-CRL or HTTP-CRL</title>
      <link>https://community.extremenetworks.com/t5/hero-product-suggestions/nac-flexible-configuration-of-trusted-root-certificates-with/m-p/58420#M31</link>
      <description>&lt;P&gt;Today several different Trusted Root Certificates can be used in NAC (Control). With using of CRLs there are some restrictions limiting the use of certificates:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;only HTTP-CRLs are supported - default Active-Directory CRL is via LDAP&lt;/LI&gt;	&lt;LI&gt;if one of the PKIs behind a root certificate does not support CRL you have to disable CRL checking for all certificates&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What we need:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;flexible configuration of certificate path (PKI, protocol, CRL) individually for every single certificate&lt;/LI&gt;	&lt;LI&gt;adding LDAP CRL checking function&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 15:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-product-suggestions/nac-flexible-configuration-of-trusted-root-certificates-with/m-p/58420#M31</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2020-11-11T15:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC: flexible configuration of Trusted Root Certificates with LDAP-CRL or HTTP-CRL</title>
      <link>https://community.extremenetworks.com/t5/hero-product-suggestions/nac-flexible-configuration-of-trusted-root-certificates-with/m-p/58421#M32</link>
      <description>&lt;P&gt;Volker,&lt;BR /&gt;&lt;BR /&gt;Ability to configure and enable distinct CRLs for different CAs is submitted to engineering, CR ID XMC-3412. If all goes well, we will see it delivered in July/Aug XIQ-SE release.&lt;BR /&gt;LDAP CRL will not be implemented, as in your use-case with AD it takes one click on MSFT side to enable CRL publishing on web server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Alex Nonikov&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 19:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-product-suggestions/nac-flexible-configuration-of-trusted-root-certificates-with/m-p/58421#M32</guid>
      <dc:creator>AlexN</dc:creator>
      <dc:date>2021-04-01T19:23:00Z</dc:date>
    </item>
  </channel>
</rss>

