cancel
Showing results for 
Search instead for 
Did you mean: 

NAC EAP-TLS + Microsoft PKI - custom subject/common name not possible

NAC EAP-TLS + Microsoft PKI - custom subject/common name not possible

AntonS
Contributor II
We have a working setup with Netsight/NAC + Microsoft Windows PKI 2012 R2
Our Clients get Certificates with Auto Enrollment, which they use to authenticate in the network.
Additionally we use LDAP User Groups to put the Clients into different Networks -> UserVLAN, AdminVLAN, InternetVLAN etc.
This works great, but we noticed a problem.
When using a non Windows Device it is possible to set a different Username/Identity that is sent to the Authentication Server.
This can be used to get into a different network than supposed to, if the Username/Identy is valid (eg. Admin)

613175a82d9e46b2bd79a46f60e511af_RackMultipart20180720-22629-vtp2y2-CaptureIphone1_inline.png



613175a82d9e46b2bd79a46f60e511af_RackMultipart20180720-121465-6c02gr-CaptureUSER1_inline.jpg



In another area we used RADIUS User Group to seperate those client families, but this is not possible here because in the certificate from User and Admin there is nothing different than the hostname.

We thought of writing something in the Subject/common name of the Certificate/Template in the PKI. But we don't know how this can be achieved since there is no possibility to write CUSTOM Information.

613175a82d9e46b2bd79a46f60e511af_RackMultipart20180720-123696-i3blh5-CaptureTemplate1_inline.jpg



Any MCSE knows how to deal with that? 😉

11 REPLIES 11

AntonS
Contributor II
Thank you for your replies
The radius property seems to do exactly what we want.
I cannot test it at the moment as our certificates don't have a subject/common name so the username cannot be replaced
when the clients have the new certificate we gonna test it

Keene__Scott
Extreme Employee
Hello,

If I am reading this correct, you can use an Appliance Property pushed out to the NAC appliance to ensure that the username matches the Common Name. This came up once in a troubleshoot so we created a knowledge-base article for it:

https://gtacknowledge.extremenetworks.com/articles/How_To/Configure-NAC-To-Use-The-TLS-Client-Certif...

Does this help?

Regards,

Scott Keene
NMS/NAC Support, Extreme GTAC

Very good, thank you. I only had time to read the initial inquiry and I remember writing the article so I just replied real quick. Take care. -Scott

StephanH
Valued Contributor III
Hello Scott,

I posted that link one hour ago .

Best regards
Stephan
Regards Stephan
GTM-P2G8KFN