Blog
Notes from the BlueCore lab: network access control, identity and policy, measured rather than assumed.
EAP-TLS on Cisco ISE 3.5: what the defaults let through, and how we proved it without a single switch
A revoked certificate got full access, a certificate with no clientAuth was accepted, and a dead OCSP responder went unnoticed. All measured on ISE 3.5 with openssl, eapol_test and radclient, and no network hardware at all.
How much of Cisco ISE 3.5 can you actually automate through the API?
We built an 802.1X and MAB policy on ISE 3.5 API-first and measured where the API stops. More of it is reachable than we expected, and the gaps are not where the documentation suggests.