<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with EAP-TLS authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496705#M308239</link>
    <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm struggling to find an issue with the EAP-TLS authentication. It seems the AAA sends the request for the client certs three times and then ends the conversation. I verified that the client sends the certificates. The obvious conclusion is that the client certs are somehow incorrect but how do I debug a problem like this? (AAA log below)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;AAA log:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:25 ss-aaa-01 radiusd[26593]: [ID 376206 local1.info] INFO RADOP(147) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Sending TLS start for EAP-Type=TLS to client.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;May 18 14:55:25 ss-aaa-01 radiusd[26593]: [ID 929614 local1.notice] NTCE RADOP(271) Performing OTA provisioning for user 001D88093B2C from 127.0.0.2[]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:25 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=9) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:26 ss-aaa-01 radiusd[26593]: [ID 447184 local1.info] INFO RADOP(149) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Entering TLS state=certificate request for EAP-type=TLS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:26 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=125) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:27 ss-aaa-01 radiusd[26593]: [ID 727110 local1.info] INFO RADOP(148) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Sending next fragment for EAP-Type=TLS to client.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:27 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=9) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:28 ss-aaa-01 radiusd[26593]: [ID 727110 local1.info] INFO RADOP(148) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Sending next fragment for EAP-Type=TLS to client.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:28 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=9) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:08:44 GMT</pubDate>
    <dc:creator>christian.scheid</dc:creator>
    <dc:date>2019-03-11T00:08:44Z</dc:date>
    <item>
      <title>Problem with EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496705#M308239</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm struggling to find an issue with the EAP-TLS authentication. It seems the AAA sends the request for the client certs three times and then ends the conversation. I verified that the client sends the certificates. The obvious conclusion is that the client certs are somehow incorrect but how do I debug a problem like this? (AAA log below)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;AAA log:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:25 ss-aaa-01 radiusd[26593]: [ID 376206 local1.info] INFO RADOP(147) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Sending TLS start for EAP-Type=TLS to client.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;May 18 14:55:25 ss-aaa-01 radiusd[26593]: [ID 929614 local1.notice] NTCE RADOP(271) Performing OTA provisioning for user 001D88093B2C from 127.0.0.2[]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:25 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=9) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:26 ss-aaa-01 radiusd[26593]: [ID 447184 local1.info] INFO RADOP(149) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Entering TLS state=certificate request for EAP-type=TLS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:26 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=125) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:27 ss-aaa-01 radiusd[26593]: [ID 727110 local1.info] INFO RADOP(148) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Sending next fragment for EAP-Type=TLS to client.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:27 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=9) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:28 ss-aaa-01 radiusd[26593]: [ID 727110 local1.info] INFO RADOP(148) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 127.0.0.2[] challenged: Sending next fragment for EAP-Type=TLS to client.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN&gt;May 18 14:55:28 ss-aaa-01 radiusd[26593]: [ID 695967 local1.info] INFO RADOP(23) auth for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:001D88093B2C@clearwire-wmx.net" target="_blank"&gt;001D88093B2C@clearwire-wmx.net&lt;/A&gt;&lt;SPAN&gt; from 172.27.134.249[] via proxy 127.0.0.2[samsung-strip-keys-mppe] (RTT=9) challenged.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496705#M308239</guid>
      <dc:creator>christian.scheid</dc:creator>
      <dc:date>2019-03-11T00:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496706#M308240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;attached a more detailed trace log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 00:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496706#M308240</guid>
      <dc:creator>christian.scheid</dc:creator>
      <dc:date>2010-05-19T00:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496707#M308241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;As per your query,&amp;nbsp; we require certificate on client, if we want to deploy EAP-TLS. Basically there are 3 certificates in this scenerio.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;[1] CA root certificate&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;[2] Server Certificate (Issued by same CA)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;[3] Client Certificate (Issued by same CA)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;[1] and [2] need to be installed on ACS server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;[1] and [3] need to be installed on Client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;In this method, Server will first validate client by verifying that it has a valid certificate issued by CA. Then Client will validate certificate issued to ACS server by CA. After that a session will be created, and all communication will take place between ACS and client through an encrypted tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Since this is not working in your scenarion then you need to upload the package.cab file from the ACS for the RCA. Do you see "SSL handshake failure error message in the ACS reports and activity &amp;gt; failed attempts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If you are not aware how to generate package.cab file from the ACS on full logging level then please let me know what platform are we running on, Is that ACS appliance or ACS windows, I will send you the steps.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;You may go through the below listed guide&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_white_paper09186a008009256b.shtml"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_white_paper09186a008009256b.shtml&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 01:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-eap-tls-authentication/m-p/1496707#M308241</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-05-19T01:22:11Z</dc:date>
    </item>
  </channel>
</rss>

