06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9 System Configuration: Authentication and Certificates<br />

OL-14386-02<br />

About Certification and EAP Protocols<br />

Note If you have previously installed a certificate to support EAP-TLS or PEAP user authentication,<br />

or to support HTTPS protection of remote ACS administration, you do not need to per<strong>for</strong>m this<br />

step. A single server certificate is sufficient to support all certificate-based ACS services and<br />

remote administration; however, EAP-TLS and PEAP require that the certificate be suitable <strong>for</strong><br />

server authentication purposes.<br />

Step 2 Enable PEAP on the Global Authentication Setup page. You use ACS to complete this step only after<br />

you have successfully completed Step 1. For detailed steps, see Configuring Authentication Options,<br />

page 9-21.<br />

Step 3 Configure a user database. To determine which user databases support PEAP authentication, see<br />

Authentication Protocol-Database Compatibility, page 1-8.<br />

ACS is ready to per<strong>for</strong>m PEAP authentication <strong>for</strong> most users. For more in<strong>for</strong>mation, see PEAP and the<br />

Unknown <strong>User</strong> Policy, page 9-8.<br />

Step 4 Consider enabling the Unknown <strong>User</strong> Policy to simplify PEAP authentication. For more in<strong>for</strong>mation, see<br />

PEAP and the Unknown <strong>User</strong> Policy, page 9-8. For detailed steps, see Configuring the Unknown <strong>User</strong><br />

Policy, page 15-8.<br />

EAP-FAST Authentication<br />

About EAP-FAST<br />

This section contains:<br />

About EAP-FAST, page 9-9<br />

About Master Keys, page 9-11<br />

About PACs, page 9-12<br />

Provisioning Modes, page 9-13<br />

Types of PACs, page 9-13<br />

EAP-FAST <strong>for</strong> Anonymous TLS Renegotiation, page 9-16<br />

PAC Free EAP-FAST, page 9-16<br />

EAP-FAST PKI Authorization Bypass, page 9-16<br />

Master Key and PAC TTLs, page 9-17<br />

Replication and EAP-FAST, page 9-17<br />

Enabling EAP-FAST, page 9-19<br />

The EAP Flexible Authentication via <strong>Secure</strong>d Tunnel (EAP-FAST) protocol is a new, publicly accessible<br />

IEEE 802.1X EAP type that <strong>Cisco</strong> developed to support customers that cannot en<strong>for</strong>ce a strong password<br />

policy and want to deploy an 802.1X EAP type that does not require digital certificates. EAP-FAST<br />

supports a variety of user and password database types, password change and expiration; and is flexible,<br />

easy to deploy, and easy to manage. For more in<strong>for</strong>mation about EAP-FAST and comparison with other<br />

EAP types, see:<br />

www.cisco.com/en/US/products/hw/wireless/ps430/products_qanda_item09186a00802030dc.shtml<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

9-9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!