<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 certificate issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727199#M247855</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lieven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the CN value appear in the client machine that you are testing with, does it show the correct username format that you are looking for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create a snap in using the mmc tool and then point it to your certificates. Then under the user's personal certificate store see what certificate is being passed to the ACS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the username attribute is stored else (Subject Alternative Name) please make the changes on the ACS and see if that moves things along.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jul 2011 05:45:20 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2011-07-06T05:45:20Z</dc:date>
    <item>
      <title>ACS 5.2 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727198#M247853</link>
      <description>&lt;P&gt;dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are encountering a certificate issue when a pc tries to log on using dot1x (eap-tls).&lt;/P&gt;&lt;P&gt;&lt;A href="https://hictatriuse031v/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=22047+Principal+username+attribute+is+missing+in+client+certificate&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" target="_self" title="Click for failure reason details"&gt;22047 Principal username attribute is missing in client certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We define in "certificate authentication profile" a profile using the subject&lt;/P&gt;&lt;P&gt;of the certificate as the user principle. Why does ACS keep saying that &lt;/P&gt;&lt;P&gt;the user principle attribute is empty ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note : We do not have this problem using ACS 4.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Lieven Stubbe&lt;/P&gt;&lt;P&gt;Belgian Railways&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727198#M247853</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2019-03-11T01:11:29Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727199#M247855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lieven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the CN value appear in the client machine that you are testing with, does it show the correct username format that you are looking for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create a snap in using the mmc tool and then point it to your certificates. Then under the user's personal certificate store see what certificate is being passed to the ACS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the username attribute is stored else (Subject Alternative Name) please make the changes on the ACS and see if that moves things along.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 05:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727199#M247855</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-06T05:45:20Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727200#M247857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been testing wireless telephony with Ascom i62 wireless handsets using EAP-TLS. Initial dot1x authentication is successful. Reauthentication sometimes fail on Cisco ACS Version 5.2.0.26.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same error mesage was displayed.&lt;/P&gt;&lt;P&gt;&lt;A href="https://hictatriuse031v/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=22047+Principal+username+attribute+is+missing+in+client+certificate&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" target="_self"&gt;22047 Principal username attribute is missing in client certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Only rebooting the phone fixes this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are we hitting bug CSCtn26538 ?&lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtn26538&amp;amp;from=summary"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtn26538&amp;amp;from=summary&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 12:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727200#M247857</guid>
      <dc:creator>pverstegen</dc:creator>
      <dc:date>2011-09-21T12:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727201#M247859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got similar problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Identity source, I use an identity store sequence:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Certificate based (using Principal Username X509 Attribute: Common Name)&lt;/LI&gt;&lt;LI&gt;Attribute retrieval search list: LDAP server&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use machine certificate...&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="74650" __jive_id="74650" alt="username.PNG" class="jive-image-thumbnail jive-image" height="31" src="https://community.cisco.com/username.PNG" width="657" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username is found in ACS View but I got the authentication error: &lt;/P&gt;&lt;P&gt;&lt;EM&gt;22047 Principal username attribute is missing in client certificate&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jan 2012 10:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727201#M247859</guid>
      <dc:creator>Patrick Tran</dc:creator>
      <dc:date>2012-01-31T10:31:53Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727202#M247861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you been able to solve this problem, we have the same issue with ACS 5.4.0.46.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 13:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-certificate-issue/m-p/1727202#M247861</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2013-04-18T13:32:42Z</dc:date>
    </item>
  </channel>
</rss>

