<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 - Authentication with AD -UPN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512016#M253850</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/0/4/9401-ACS%205%20Access%20Services.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;what protocols are you using for your ACS 5 Access Service (see above) - do you have MS-CHAPv2 enabled? if you are using a valid UPN username for your AD it sounds like you have a different issue to me.&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Dec 2010 15:59:54 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2010-12-08T15:59:54Z</dc:date>
    <item>
      <title>ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512009#M253843</link>
      <description>&lt;P&gt;I am trying to configure RADUIS authentification using the UPN as a userame.&lt;/P&gt;&lt;P&gt;I always receive the following error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;22056 Subject not found in the applicable identity store (s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does any oun know why&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick Roch&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512009#M253843</guid>
      <dc:creator>PATRICK ROCH</dc:creator>
      <dc:date>2019-03-26T00:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512010#M253844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That message means that the ACS retrieved the string from the client credentials and tried to authenticate it against the configured identity store, however that username was not found there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please elaborate more about your setup?&lt;/P&gt;&lt;P&gt;What is the EAP method? PEAP/EAP-FAST/EAP-TLS?&lt;/P&gt;&lt;P&gt;And the inner authnetication method? MS-CHAPv2?&lt;/P&gt;&lt;P&gt;Are you using certs based authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the Identity store? AD/LDAP/Internal ACS DB?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the username on that failed attempt log? Is that what you were expecting to see?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 10:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512010#M253844</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-08T10:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512011#M253845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello - i was about to post a similar topic when i found this thread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we're currently using ACS 4.0 to authenticate wireless users (PEAP) against Active Directory. this works fine and if a user logs in as &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:j.bloggs@acme.com"&gt;j.bloggs@acme.com&lt;/A&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:j.bloggs@another.acme.com"&gt;j.bloggs@another.acme.com&lt;/A&gt;&lt;SPAN&gt;, ACS 4.0 strips the suffix and sends the username as j.bloggs to AD (see link below)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://cisco.biz/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/d.html#wp353993"&gt;http://cisco.biz/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/d.html#wp353993&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm having a problem duplicating this suffix removal for PEAP authentication in ACS 5 (running 5.1.0.44 in a VM). i found the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-13714?decorator=print"&gt;https://supportforums.cisco.com/docs/DOC-13714?decorator=print&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this works fine for PAP_ASCII but not for PEAP (EAP-MSCHAPv2) - any ideas on how to acheive this in ACS 5?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 13:12:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512011#M253845</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2010-12-08T13:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512012#M253846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thank for replys to my posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration is using an external DB witch is ActiveDirectory.&lt;/P&gt;&lt;P&gt;We are doing PEAP and EAP-FAST both with MS-CHAP v2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we use the normal username (j.doe), it work, so my communication with AD is good.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is when we use the UPN that it doen't. (&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:john.doe@acme.com"&gt;john.doe@acme.com&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512012#M253846</guid>
      <dc:creator>PATRICK ROCH</dc:creator>
      <dc:date>2010-12-08T15:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512013#M253847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for replying to my post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using an external DB witch is AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using PEAP and EAP-Fast with MS-CHAP-V2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The setup work fin when we use the normal AD username (ex. j.doe) But when for the same user I what to use the UPN (&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:john.doe@acme.com"&gt;john.doe@acme.com&lt;/A&gt;&lt;SPAN&gt;) it is then that I receive the error message.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512013#M253847</guid>
      <dc:creator>PATRICK ROCH</dc:creator>
      <dc:date>2010-12-08T15:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512014#M253848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;is "acme.com" a valid UPN suffix on your AD domain? i can authenticate users ok if their UPN suffix is valid - problem is that some users use non-valid UPN suffix's and i need to get ACS 5 to strip the suffix before its sent to AD (i.e. like ACS 4 does). if i can't get that working i'll have to see about adding all the possible UPN suffixs to the AD.&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512014#M253848</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2010-12-08T15:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512015#M253849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;acme.com for me is an exemple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but, in the configuration of the AD external identity sotre, my Active Directory Domain Name is : SIM.acme.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And the UPN configure for my users are &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:john.doe@acme.com"&gt;john.doe@acme.com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; Could this be a source of my trouble, and if so, I can I make it work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when I go in the Directoy attribute tab, and I enter the username j.doe, and do select, it retreive the fuul attribute for that user and I see the UPN. Why I cannot use it I don't know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also this work in ACS 4.2......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512015#M253849</guid>
      <dc:creator>PATRICK ROCH</dc:creator>
      <dc:date>2010-12-08T15:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512016#M253850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/0/4/9401-ACS%205%20Access%20Services.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;what protocols are you using for your ACS 5 Access Service (see above) - do you have MS-CHAPv2 enabled? if you are using a valid UPN username for your AD it sounds like you have a different issue to me.&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512016#M253850</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2010-12-08T15:59:54Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 - Authentication with AD -UPN</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512017#M253851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone have a solution for an EAP-PEAPv0/MSCHAPv2 authentication with the UPN as username?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 14:06:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-authentication-with-ad-upn/m-p/1512017#M253851</guid>
      <dc:creator>Lukas Bielinski</dc:creator>
      <dc:date>2013-09-04T14:06:51Z</dc:date>
    </item>
  </channel>
</rss>

