<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Wlan user authentication fails for users with umlaut in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-wlan-user-authentication-fails-for-users-with-umlaut/m-p/2076204#M161750</link>
    <description>&lt;DIV&gt;&lt;P&gt;We have setup a Cisco Identity Services Engine to manage WLAN&amp;nbsp; access for our users. Access should be granted to users from a specific Windows Active&amp;nbsp; Directory group. This works fine for users having a username consisting only of ASCII&amp;nbsp; letters. However, user names having e.g. an umlaut fail. The live&amp;nbsp; authentication log shows an error "22056 Subject not found in the&amp;nbsp; applicable identity store(s)".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what could be wrong? (And, no, renaming all non-ASCII users is not an option)&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: &lt;/P&gt;&lt;P&gt;Remarkably, the AD group name happens to also have an umlaut, so there is no general problem with them.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:56:16 GMT</pubDate>
    <dc:creator>Andreas Hoffmann</dc:creator>
    <dc:date>2019-03-11T02:56:16Z</dc:date>
    <item>
      <title>Cisco ISE Wlan user authentication fails for users with umlaut</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-wlan-user-authentication-fails-for-users-with-umlaut/m-p/2076204#M161750</link>
      <description>&lt;DIV&gt;&lt;P&gt;We have setup a Cisco Identity Services Engine to manage WLAN&amp;nbsp; access for our users. Access should be granted to users from a specific Windows Active&amp;nbsp; Directory group. This works fine for users having a username consisting only of ASCII&amp;nbsp; letters. However, user names having e.g. an umlaut fail. The live&amp;nbsp; authentication log shows an error "22056 Subject not found in the&amp;nbsp; applicable identity store(s)".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what could be wrong? (And, no, renaming all non-ASCII users is not an option)&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: &lt;/P&gt;&lt;P&gt;Remarkably, the AD group name happens to also have an umlaut, so there is no general problem with them.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-wlan-user-authentication-fails-for-users-with-umlaut/m-p/2076204#M161750</guid>
      <dc:creator>Andreas Hoffmann</dc:creator>
      <dc:date>2019-03-11T02:56:16Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE Wlan user authentication fails for users with umlaut</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-wlan-user-authentication-fails-for-users-with-umlaut/m-p/2076205#M161823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The solution I finally was content with is as follows: It turns out that the Windows AD login does not really differentiate between umlauts and their dotless counterparts. That is, it has always been possible for a user named "Müller" to login e.g. to a Windows workstation using "Muller" (or a suer named "Hoffmann" could as well have used "Höffmänn" as login name). Consequently, using the umlaut-less alternative for WLAN-authentication works out of the box. So we can keep the correct spelling in AD and users can most of th etime use their correct spelling to login - only when logging in to the company WLAN they need to drop the dieresis. This is somewhat unusual because user might expect that umlauts would be replaced per ä-&amp;gt;ae, ö-oe, ü-&amp;gt;ue instead of just ä-&amp;gt;a, ö-&amp;gt;o, ü-&amp;gt;u. But at least it allows us to keep the correctly spelled names in the directory and no special modification to allow user login (except teaching the users)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 15:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-wlan-user-authentication-fails-for-users-with-umlaut/m-p/2076205#M161823</guid>
      <dc:creator>Andreas Hoffmann</dc:creator>
      <dc:date>2013-08-07T15:10:16Z</dc:date>
    </item>
  </channel>
</rss>

