Specifications
Cisco Systems, Inc.
All contents are Copyright © 1992–2002 Cisco Systems, Inc. All rights reserved. Important Notices and Privacy Statement.
Page 23 of 42
6.2.2 System Configuration Parameters on ACS
After obtaining the ACS server certificate from the enterprise root certification authority server, the following steps
were used to configure the ACS for EAP-TLS (and LEAP) authentication:
1. On the ACS menu, choose System Configuration >> ACS Certificate Setup.
2. Under ACS Certificate Setup, choose “Use existing certificate” and then the “Specify certificate from storage”
option. Specify the name of the ACS certificate obtained from the certification authority server (in our example,
“ACS-TMELAB” was specified in Section 6.2.1). Click Submit.
3. On the ACS menu, choose System Configuration >> “Certification Authority Setup.” Click “Edit certificate trust
list” and select the name(s) of the certification authority server(s) that were used to issue certificates to the ACS
device(s) and EAP-TLS clients.
Note:
The certificate trust list (CTL) has to be used when the root certification authority (ex: Root_CA_A) that
issued the ACS certificate and the rootcertification authority that issuedthe client(s) certificate (Root_CA_B) are not
the same. In this scenario, Root_CA_B has to be added to the ACS trust list. To do this, add the certificate of
Root_CA_B to the ACS CTL. By default, ACS trusts certificates that were issued from the same root certification
authority that issues its certificate. In our example (in the Validation Lab), we used the same root certification
authority to obtain the ACS and client certificates; thus, the ACS will automatically trust the client certificates and
you do not need to edit the CTL.
4. Choose the ACS menu and choose System Configuration >> Global Authentication Setup. Select the “Allow
EAP-TLS ...” option and click the “Submit+Restart” button.
The following figures illustrate the above steps needed to configure the ACS for EAP-TLS:
Figure 6-6 shows the System Configuration menu options for EAP-TLS setup on the ACS.