Has anyone used EAP-TLS where a Windows device has multiple client certs loaded in the personal store? Is there a way to force it via GPO to choose one cert over the other to use for authentication? The user certs from ADCS don’t always contain a private key in the personal store except on the first device a user logs into, so we moved to SecureW2 to guarantee it would work. In Cisco ISE I trust both ADCS and SecureW2 CAs. What is happening and what I’m trying to achieve is:
1. if a computer happens to have an ADCS User cert private key, it uses that one first and I want to try to force it to use the SecureW2 cert via GPO or some setting 2. For machine auth, I want it to always use the ADCS cert since there’s no private key issue. There is no SecureW2 machine cert. Due to this I don’t think I can just say “only use certs from this Issuer CA” because I need both, unless I can do that for user and machine separately. Thanks, Lynn Heavrin Network Engineer III | Network Engineering Washington University in St. Louis ________________________________ The materials in this message are private and may contain Protected Healthcare Information or other information of a sensitive nature. If you are not the intended recipient, be advised that any unauthorized use, disclosure, copying or the taking of any action in reliance on the contents of this information is strictly prohibited. If you have received this email in error, please immediately notify the sender via telephone or return mail. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community