Contents
xx
User Guide for Cisco Secure Access Control System 5.3
OL-24201-01
Overview of EAP-TLS B-6
User Certificate Authentication B-6
PKI Authentication B-7
PKI Credentials B-8
PKI Usage B-8
Fixed Management Certificates B-9
Importing Trust Certificates B-9
Acquiring Local Certificates B-9
Importing the ACS Server Certificate B-10
Initial Self-Signed Certificate Generation B-10
Certificate Generation B-10
Exporting Credentials B-11
Credentials Distribution B-12
Hardware Replacement and Certificates B-12
Securing the Cryptographic Sensitive Material B-12
Private Keys and Passwords Backup B-13
EAP-TLS Flow in ACS 5.3 B-13
PEAPv0/1 B-14
Overview of PEAP B-15
Supported PEAP Features B-15
PEAP Flow in ACS 5.3 B-17
Creating the TLS Tunnel B-17
Authenticating with MSCHAPv2 B-18
EAP-FAST B-18
Overview of EAP-FAST B-18
EAP-FAST Benefits B-20
EAP-FAST in ACS 5.3 B-20
About Master-Keys B-21
About PACs B-21
Provisioning Modes B-22
Types of PACs B-22
ACS-Supported Features for PACs B-24
Master Key Generation and PAC TTLs B-26
EAP-FAST for Allow TLS Renegotiation B-26
EAP-FAST Flow in ACS 5.3. B-26
EAP-FAST PAC Management B-27
Key Distribution Algorithm B-28
EAP-FAST PAC-Opaque Packing and Unpacking B-28
Revocation Method B-28
PAC Migration from ACS 4.x B-29