<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wireless Authentication problem in ISE version 2.0.0.306 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580092#M268</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi guys,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I had a Cisco ISE 2.0.0.306,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I config authentication on wired and wireless, wired authentication works exactly, however wireless authentication gave following problem:&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Failure Reason:&amp;nbsp; 12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Resolution:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Check whether the proper server certificate is installed and configured for EAP in the Local Certificates page ( Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Local Certificates ). Also ensure that the certificate authority that signed this server certificate is correctly installed in client's supplicant. Check the previous steps in the log for this EAP-TLS conversation for a message indicating why the handshake failed. Check the OpenSSLErrorMessage and OpenSSLErrorStack for more information.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Root cause:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I have been attached screen shot of error, please attention to it.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;note: I have run a new version of Cisco ISE(&lt;SPAN style="color: #39393b; font-family: Arial; font-size: 14px; font-weight: bold;"&gt;2.2.0.470&lt;/SPAN&gt;) and works exactly.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;both of ISE have same configuration.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I have changed the certificates of ISE but it doesn't work &lt;SPAN style="font-size: 13.3333px;"&gt;still&lt;/SPAN&gt;.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Can you tel me, whether this is a bug in this version?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;please help me,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Mar 2017 09:27:53 GMT</pubDate>
    <dc:creator>mostafashoaei</dc:creator>
    <dc:date>2017-03-06T09:27:53Z</dc:date>
    <item>
      <title>wireless Authentication problem in ISE version 2.0.0.306</title>
      <link>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580092#M268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi guys,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I had a Cisco ISE 2.0.0.306,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I config authentication on wired and wireless, wired authentication works exactly, however wireless authentication gave following problem:&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Failure Reason:&amp;nbsp; 12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Resolution:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Check whether the proper server certificate is installed and configured for EAP in the Local Certificates page ( Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Local Certificates ). Also ensure that the certificate authority that signed this server certificate is correctly installed in client's supplicant. Check the previous steps in the log for this EAP-TLS conversation for a message indicating why the handshake failed. Check the OpenSSLErrorMessage and OpenSSLErrorStack for more information.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Root cause:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I have been attached screen shot of error, please attention to it.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;note: I have run a new version of Cisco ISE(&lt;SPAN style="color: #39393b; font-family: Arial; font-size: 14px; font-weight: bold;"&gt;2.2.0.470&lt;/SPAN&gt;) and works exactly.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;both of ISE have same configuration.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I have changed the certificates of ISE but it doesn't work &lt;SPAN style="font-size: 13.3333px;"&gt;still&lt;/SPAN&gt;.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Can you tel me, whether this is a bug in this version?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;please help me,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Mar 2017 09:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580092#M268</guid>
      <dc:creator>mostafashoaei</dc:creator>
      <dc:date>2017-03-06T09:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: wireless Authentication problem in ISE version 2.0.0.306</title>
      <link>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580093#M269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;99% of the time this is because the endpoint does not trust the certificate provided by ISE. This is because you are&lt;/P&gt;&lt;P&gt;1) using a self-signed certificate or &lt;/P&gt;&lt;P&gt;2) the endpoint does not trust one of the signers in the certificate chain&lt;/P&gt;&lt;P&gt;Either you are not using a public CA to sign the ISE certificate or the wireless endpoint does not have your enterprise CA certificate installed in its trust store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend asking questions about ISE in the &lt;A href="https://community.cisco.com/space/5301"&gt;Identity Services Engine (ISE)&lt;/A&gt; group unless you are asking about APIs which is more appropriate for DevNet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Mar 2017 17:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580093#M269</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2017-03-06T17:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: wireless Authentication problem in ISE version 2.0.0.306</title>
      <link>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580094#M270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dear Thomas&lt;/P&gt;&lt;P&gt;I've checked certificate, Certificate of ISE signed by my domain.&lt;/P&gt;&lt;P&gt;I've imported root CA of domain on the client as trusted certificate.&lt;/P&gt;&lt;P&gt;note: I have another ISE(2.2) with same config, it works fine without any problem, but I have issue in this version.&lt;/P&gt;&lt;P&gt;I asked this question on Identity services engine (ISE) now. &lt;A _jive_internal="true" href="https://community.cisco.com/message/248335#248335"&gt;https://communities.cisco.com/message/248335#248335&lt;/A&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for your answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Mar 2017 05:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireless-authentication-problem-in-ise-version-2-0-0-306/m-p/3580094#M270</guid>
      <dc:creator>mostafashoaei</dc:creator>
      <dc:date>2017-03-07T05:40:13Z</dc:date>
    </item>
  </channel>
</rss>

