<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>BlueCore blog</title>
    <link>https://bluecore.joburg/blog/</link>
    <atom:link href="https://bluecore.joburg/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Notes from the BlueCore lab on network access control, identity and policy.</description>
    <language>en-za</language>
    <lastBuildDate>Tue, 15 Sep 2026 06:00:00 +0000</lastBuildDate>
    <item>
      <title>EAP-TLS on Cisco ISE 3.5: what the defaults let through, and how we proved it without a single switch</title>
      <link>https://bluecore.joburg/blog/ise-eap-tls-without-hardware/</link>
      <guid isPermaLink="true">https://bluecore.joburg/blog/ise-eap-tls-without-hardware/</guid>
      <pubDate>Tue, 15 Sep 2026 06:00:00 +0000</pubDate>
      <description>A revoked certificate got full access, a certificate with no clientAuth was accepted, and a dead OCSP responder went unnoticed. All measured on ISE 3.5 with openssl, eapol_test and radclient, and no network hardware at all.</description>
    </item>
    <item>
      <title>How much of Cisco ISE 3.5 can you actually automate through the API?</title>
      <link>https://bluecore.joburg/blog/ise-api-coverage/</link>
      <guid isPermaLink="true">https://bluecore.joburg/blog/ise-api-coverage/</guid>
      <pubDate>Tue, 15 Sep 2026 06:00:00 +0000</pubDate>
      <description>We built an 802.1X and MAB policy on ISE 3.5 API-first and measured where the API stops. More of it is reachable than we expected, and the gaps are not where the documentation suggests.</description>
    </item>
  </channel>
</rss>
