why u need to select the certificate ? why the browser do not select it automatically ? in sll the server do not send which Ca certificate accepted for authentication ?
Date: Thu, 22 Dec 2011 18:33:46 +0530 From: [email protected] To: [email protected] CC: [email protected] Subject: Re: [OSL | CCIE_Security] WebVPN Certiticate authentication plus radius authorization The configuration worked as expected, I didn't do anything. With regards Kings On Thu, Dec 22, 2011 at 5:29 PM, Fawad Khan <[email protected]> wrote: How? On Thursday, December 22, 2011, Kingsley Charles <[email protected]> wrote: > Got it working..... > > On Thu, Dec 22, 2011 at 3:56 PM, Kingsley Charles > <[email protected]> wrote: >> >> Hi all >> >> I have configured CA server on an ASA and have downloaded the web >> certificate to the client PC. Now from the client PC, when I try to launch >> WebVPN portal, I get a pop up to select >> the ceritificate. I select it and then get the regular webvpn authentication >> page. >> >> Why I am being prompted when I have just configured for certification >> authentication. >> >> Also one step ahead, I trying to authenticate the CN from the certificate >> using a radius server but that doesn't work Any thoughts? >> >> tunnel-group king type remote-access >> tunnel-group king general-attributes >> authorization-server-group rad >> authorization-required >> username-from-certificate CN >> tunnel-group king webvpn-attributes >> authentication certificate >> >> Reference... >> >> http://blog.ipexpert.com/2010/07/28/asa-local-ca-server/ >> >> With regards >> Kings > > -- FNK _______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com Are you a CCNP or CCIE and looking for a job? Check out www.PlatinumPlacement.com
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com Are you a CCNP or CCIE and looking for a job? Check out www.PlatinumPlacement.com
