06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9 System Configuration: Authentication and Certificates<br />

Master Key and PAC TTLs<br />

Replication and EAP-FAST<br />

OL-14386-02<br />

About Certification and EAP Protocols<br />

handshake with a CRL or an external database lookup. If PKI Authorization Bypass would be able to<br />

implemented without PAC Free EAP- FAST, the user would be issued a PAC and access to the network<br />

would not be revoked until the PAC expired.<br />

The TTL values <strong>for</strong> master keys and PACs determine their states, as described in About Master Keys,<br />

page 9-11 and About PACs, page 9-12. Master key and PAC states determine whether someone<br />

requesting network access with EAP-FAST requires PAC provisioning or PAC refreshing.<br />

Table 9-1 summarizes ACS behavior with respect to PAC and master key states.<br />

Table 9-1 Master Key versus PAC States<br />

Master key state PAC active PAC expired<br />

Master key active Phase one succeeds.<br />

Phase one succeeds.<br />

PAC is not refreshed at end of phase two. PAC is refreshed at end of phase two.<br />

Master key retired Phase one succeeds.<br />

Phase one succeeds.<br />

PAC is refreshed at end of phase two.<br />

PAC is refreshed at end of phase two.<br />

Master key expired PAC provisioning is required.<br />

PAC provisioning is required.<br />

If automatic provisioning is enabled, phase zero If automatic provisioning is enabled, phase zero<br />

occurs and a new PAC is sent. The end-user client occurs and a new PAC is sent. The end-user client<br />

initiates a new EAP-FAST authentication request initiates a new EAP-FAST authentication request<br />

using the new PAC.<br />

using the new PAC.<br />

If automatic provisioning is disabled, phase zero If automatic provisioning is disabled, phase zero<br />

does not occur and phase one fails. You must use does not occur and phase one fails. You must use<br />

manual provisioning to give the user a new PAC. manual provisioning to give the user a new PAC.<br />

The Database Replication feature supports the replication of EAP-FAST settings, Authority ID, and<br />

master keys. Replication of EAP-FAST data occurs only if on the:<br />

Database Replication Setup page of the primary ACS, under Send, you have checked the EAP-FAST<br />

master keys and policies check box.<br />

Global Authentication Setup page of the primary ACS, you have enabled EAP-FAST and checked<br />

the EAP-FAST master server check box.<br />

Database Replication Setup page of the secondary ACS, under Receive, you have checked the<br />

EAP-FAST master keys and policies check box.<br />

Global Authentication Setup page of the secondary ACS, you have enabled EAP-FAST and<br />

unchecked the EAP-FAST master server check box.<br />

EAP-FAST-related replication occurs <strong>for</strong> three events:<br />

Generation of master keys—A primary ACS sends newly generated active and backup master keys<br />

to secondary ACSs. This event occurs immediately after master key generation, provided that you<br />

configure the replication properly and it is not affected by replication scheduling on the Database<br />

Replication Setup page.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

9-17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!