<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 error 22056 Subject not found in the applicable identity store(s) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/3227390#M189727</link>
    <description>I have the same problem, the version of the ACS is 5.6.0.22, The OS in the client users is Windows 7. The users have the certificate company installed but some times the users are authenticated sucessfull and other I see the error ​22056 Subject not found in the applicable identity store(s), I have to enable the MAC address in the local store, when the PC has a connection to the network, restarting the PC and delete the MAC address in the local store the PC works fine.</description>
    <pubDate>Tue, 05 Dec 2017 20:41:46 GMT</pubDate>
    <dc:creator>david.perez</dc:creator>
    <dc:date>2017-12-05T20:41:46Z</dc:date>
    <item>
      <title>ACS 5.2 error 22056 Subject not found in the applicable identity store(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/2042982#M189724</link>
      <description>&lt;P&gt;Hi, I have two ACS v 5.2 (primary and secundary) and some users are in the internal stor and the others are in the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local site topology is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC - AP - WLC - ACS - AD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication method is PEAP(EAP-MSCHAPv2) and all user have the certificate company installed. The OS in the client users is Windows 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users was working fine but some users reports intranet disconnections. I see in the ACS log&amp;nbsp; many "22056 Subject not found in the applicable identity store(s)." and "24415 User authentication against Active Directory failed since user's account is locked out" alarms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believed it was because user wasn´t in the AD data base, but some times the same user is authenticated successfull and other i see the "22056...." or "24415...." alarms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I switched the role for ACS primary to works as secundary and we see the same alarms.&lt;/P&gt;&lt;P&gt;I don´t know is an ACS issue and how do i resolve it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please helpme &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:38:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/2042982#M189724</guid>
      <dc:creator>alejandromx1</dc:creator>
      <dc:date>2019-03-11T02:38:40Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 error 22056 Subject not found in the applicable identity</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/2042983#M189725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you authenticating these users? Are they present in the ACS local database? If so, did you check the status of the internal account to see if the users account is still active and isnt disabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 02:54:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/2042983#M189725</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-08T02:54:37Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 error 22056 Subject not found in the applicable identity</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/2042984#M189726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the start, users set their username and password in&amp;nbsp;&amp;nbsp; their laptops only. Their laptops are in the company domain and wait to&amp;nbsp;&amp;nbsp; get access to the wireless company SSID.&lt;/P&gt;&lt;P&gt;The laptop has a company&amp;nbsp;&amp;nbsp; certificate and wireless profile configured as WPA2 enterprise with&amp;nbsp; AES.&amp;nbsp; PEAP with EAP-MSCHAPv2 are selected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You´re right;&amp;nbsp; When&amp;nbsp; user is successfull authenticating I saw in the ACS log that user&amp;nbsp; is&amp;nbsp; authenticating in the AD1 identity stor and I see user´s mac address&amp;nbsp; is&amp;nbsp; enabled in the local stor too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´m going to disable the user´s local account and looking for the other users are local mac adress too. I´ll post it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 04:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/2042984#M189726</guid>
      <dc:creator>alejandromx1</dc:creator>
      <dc:date>2012-10-08T04:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 error 22056 Subject not found in the applicable identity store(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/3227390#M189727</link>
      <description>I have the same problem, the version of the ACS is 5.6.0.22, The OS in the client users is Windows 7. The users have the certificate company installed but some times the users are authenticated sucessfull and other I see the error ​22056 Subject not found in the applicable identity store(s), I have to enable the MAC address in the local store, when the PC has a connection to the network, restarting the PC and delete the MAC address in the local store the PC works fine.</description>
      <pubDate>Tue, 05 Dec 2017 20:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-error-22056-subject-not-found-in-the-applicable-identity/m-p/3227390#M189727</guid>
      <dc:creator>david.perez</dc:creator>
      <dc:date>2017-12-05T20:41:46Z</dc:date>
    </item>
  </channel>
</rss>

