Reference11r2:Interfaces/ETH/802.1X: Difference between revisions
Jump to navigation
Jump to search
No edit summary |
(Customer feedback: Clarified that EAP-TLS settings re-use EAP-MD5 settings) |
||
Line 3: | Line 3: | ||
* '''Password''' Enter the shared secret for the MD5 challenge/response handshake. | * '''Password''' Enter the shared secret for the MD5 challenge/response handshake. | ||
;'''EAP-TLS''': | ;'''EAP-TLS''': | ||
The EAP-MD5 settings are going to reused for EAP-TLS needs. I.e. there's currently no extra setting for EAP-TLS. The configuration for an actual certificate, being fed into the EAP-TLS session, can be found at ''General/Certificates/Device Certificate''. | |||
* '''User''' Enter the user/identity<ref>EAP-TLS doesn't mandate that identity to necessarily be the same as the certificates subject/CN</ref> to be sent within the EAP Identity request.<ref name="user-pw">A non-empty user/password just serves as an "on"-switch</ref> | * '''User''' Enter the user/identity<ref>EAP-TLS doesn't mandate that identity to necessarily be the same as the certificates subject/CN</ref> to be sent within the EAP Identity request.<ref name="user-pw">A non-empty user/password just serves as an "on"-switch</ref> | ||
* '''Password''' Enter arbitrary content.<ref name="user-pw"/> | * '''Password''' Enter arbitrary content.<ref name="user-pw"/> |
Revision as of 11:33, 21 August 2015
- EAP-MD5
- User Enter the user/identity to authenticate with.
- Password Enter the shared secret for the MD5 challenge/response handshake.
- EAP-TLS
The EAP-MD5 settings are going to reused for EAP-TLS needs. I.e. there's currently no extra setting for EAP-TLS. The configuration for an actual certificate, being fed into the EAP-TLS session, can be found at General/Certificates/Device Certificate.
- User Enter the user/identity[1] to be sent within the EAP Identity request.[2]
- Password Enter arbitrary content.[2]
- General/Certificates/Device Certificate
- Proxy-Logoff
If the phone's LAN-port got disconnected, EAPOL-Logoff messages are going to be sent on behalf of participants connected to the phone's PC-port. An EAPOL-Logoff will be sent for each MAC-address learned from traversing EAPOL-Start messages.