<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic machine authentication not working with peap mschapv2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/machine-authentication-not-working-with-peap-mschapv2/m-p/967558#M2302</link>
    <description>&lt;P&gt;I have installed ACS ver 4.1.1 trial downloaded from cisco web sites. I have configure 802.1x machine authentication using self generated certificate with unknown user policy configure for windows database authentication. I can authenticate user via peap authentication. but i can never get the machine authentication working. on failed attempted.psv, i found EAP-TLS or PEAP authentication failed during SSL handshake. in the auth.log i found below message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PolicyMgr::CreateContext: new context id=3&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: User-Name=host/paul2.test.com&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Service-Type=2&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Framed-MTU=1500&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Called-Station-Id=00-11-93-69-C5-9A&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Calling-Station-Id=00-0E-7B-30-FA-08&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: EAP-Message=(binary value)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Message-Authenticator=(binary value)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: NAS-Port-Type=15&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: NAS-Port=50024&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: NAS-IP-Address=10.20.209.2&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: PDE-NAS-Vendor-14=1&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: PDE-Service-ID-0=0&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PolicyMgr::SelectService: context id=3; no profile was matched - using default (0)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6184 Done RQ1152, client 2, status 0&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6448     Worker 1 processing message 7.&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Start RQ1026, client 50 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6448 [PDE]: PolicyMgr::Process: request type=5; context id=3; applied default profiles (0) - do nothing&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5394 6448 Attempting authentication for Unknown User 'host/paul2.test.com'&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 1645 6448 pvAuthenticateUser: authenticate 'host/paul2.test.com' against CSDB&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Done RQ1026, client 50, status -2046&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6448     Worker 1 processing message 8.&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Start RQ1027, client 50 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0928 6448 AuthenProcessResponse: process response for 'host/paul2.test.com'&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Done RQ1027, client 50, status -2046&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6448     Worker 1 processing message 9.&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Start RQ1027, client 50 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0928 6448 AuthenProcessResponse: process response for 'host/paul2.test.com'&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 E 0381 6448 EAP: PEAP: ProcessResponse: invalid TLS data size received: 0&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0381 6448 EAP: PEAP: Second phase: 0 authentication FAILED&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Done RQ1027, client 50, status -2120&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6184     Worker 0 processing message 36.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can shed some light on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:20:37 GMT</pubDate>
    <dc:creator>andyap</dc:creator>
    <dc:date>2020-02-21T18:20:37Z</dc:date>
    <item>
      <title>machine authentication not working with peap mschapv2</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-authentication-not-working-with-peap-mschapv2/m-p/967558#M2302</link>
      <description>&lt;P&gt;I have installed ACS ver 4.1.1 trial downloaded from cisco web sites. I have configure 802.1x machine authentication using self generated certificate with unknown user policy configure for windows database authentication. I can authenticate user via peap authentication. but i can never get the machine authentication working. on failed attempted.psv, i found EAP-TLS or PEAP authentication failed during SSL handshake. in the auth.log i found below message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PolicyMgr::CreateContext: new context id=3&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: User-Name=host/paul2.test.com&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Service-Type=2&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Framed-MTU=1500&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Called-Station-Id=00-11-93-69-C5-9A&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Calling-Station-Id=00-0E-7B-30-FA-08&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: EAP-Message=(binary value)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: Message-Authenticator=(binary value)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: NAS-Port-Type=15&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: NAS-Port=50024&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: NAS-IP-Address=10.20.209.2&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: PDE-NAS-Vendor-14=1&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PdeAttributeSet::addAttribute: PDE-Service-ID-0=0&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6184 [PDE]: PolicyMgr::SelectService: context id=3; no profile was matched - using default (0)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6184 Done RQ1152, client 2, status 0&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6448     Worker 1 processing message 7.&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Start RQ1026, client 50 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0143 6448 [PDE]: PolicyMgr::Process: request type=5; context id=3; applied default profiles (0) - do nothing&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5394 6448 Attempting authentication for Unknown User 'host/paul2.test.com'&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 1645 6448 pvAuthenticateUser: authenticate 'host/paul2.test.com' against CSDB&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Done RQ1026, client 50, status -2046&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6448     Worker 1 processing message 8.&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Start RQ1027, client 50 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0928 6448 AuthenProcessResponse: process response for 'host/paul2.test.com'&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Done RQ1027, client 50, status -2046&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6448     Worker 1 processing message 9.&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Start RQ1027, client 50 (127.0.0.1)&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0928 6448 AuthenProcessResponse: process response for 'host/paul2.test.com'&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 E 0381 6448 EAP: PEAP: ProcessResponse: invalid TLS data size received: 0&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 0381 6448 EAP: PEAP: Second phase: 0 authentication FAILED&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5081 6448 Done RQ1027, client 50, status -2120&lt;/P&gt;&lt;P&gt;AUTH 03/02/2008 07:01:13 I 5094 6184     Worker 0 processing message 36.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can shed some light on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-authentication-not-working-with-peap-mschapv2/m-p/967558#M2302</guid>
      <dc:creator>andyap</dc:creator>
      <dc:date>2020-02-21T18:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication not working with peap mschapv2</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-authentication-not-working-with-peap-mschapv2/m-p/967559#M2303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Mar 2008 01:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-authentication-not-working-with-peap-mschapv2/m-p/967559#M2303</guid>
      <dc:creator />
      <dc:date>2008-03-03T01:44:24Z</dc:date>
    </item>
  </channel>
</rss>

