We have a working setup with Netsight/NAC + Microsoft Windows PKI 2012 R2
Our Clients get Certificates with Auto Enrollment, which they use to authenticate in the network.
Additionally we use LDAP User Groups to put the Clients into different Networks -> UserVLAN, AdminVLAN, InternetVLAN etc.
This works great, but we noticed a problem.
When using a non Windows Device it is possible to set a different Username/Identity that is sent to the Authentication Server.
This can be used to get into a different network than supposed to, if the Username/Identy is valid (eg. Admin)
In another area we used RADIUS User Group to seperate those client families, but this is not possible here because in the certificate from User and Admin there is nothing different than the hostname.
We thought of writing something in the Subject/common name of the Certificate/Template in the PKI. But we don't know how this can be achieved since there is no possibility to write CUSTOM Information.
Any MCSE knows how to deal with that?
😉