<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5 EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459397#M312428</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Seems to be that, or also you are not installed the CA in the ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CA Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | ________ Server Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |______________Client certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ensure that the certificate authority that signed the client's certificate is&amp;nbsp; correctly installed in the Certificate Authorities page (Users and Identity&amp;nbsp; Stores: Certificate Authorities). Check the OpenSSLErrorMessage and&amp;nbsp; OpenSSLErrorStack for more information. If CRL is configured, check the System&amp;nbsp; Diagnostics for possible CRL downloading faults.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Un Saludo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Nov 2010 13:25:35 GMT</pubDate>
    <dc:creator>jorge.novo</dc:creator>
    <dc:date>2010-11-05T13:25:35Z</dc:date>
    <item>
      <title>ACS 5 EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459396#M312427</link>
      <description>&lt;P&gt;How do we add a trust authority on ACS 5?&amp;nbsp; We also get an error when the client authenticate by eap-tls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=/home/acsadmin/Failure_Reason/Authentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=12514 EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="margin-top: 0pt; color: #ff0000;" target="_self" title="Click for failure reason details"&gt;12514 EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain&lt;/A&gt;&amp;nbsp; this sound like the Trust Authority on client is not matchi with on ACS server , is that right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459396#M312427</guid>
      <dc:creator>nhan.duong</dc:creator>
      <dc:date>2019-03-11T00:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5 EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459397#M312428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Seems to be that, or also you are not installed the CA in the ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CA Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | ________ Server Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |______________Client certificate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ensure that the certificate authority that signed the client's certificate is&amp;nbsp; correctly installed in the Certificate Authorities page (Users and Identity&amp;nbsp; Stores: Certificate Authorities). Check the OpenSSLErrorMessage and&amp;nbsp; OpenSSLErrorStack for more information. If CRL is configured, check the System&amp;nbsp; Diagnostics for possible CRL downloading faults.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Un Saludo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 13:25:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459397#M312428</guid>
      <dc:creator>jorge.novo</dc:creator>
      <dc:date>2010-11-05T13:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5 EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459398#M312429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct, the ACS doesn't have the CA for the client certificate being presented.&amp;nbsp; This can be added under Users and Identity Stores -&amp;gt; Certificate Authorties, If it is a multi-tiered CA you can add each certificate in the chain here.&lt;/P&gt;&lt;P&gt;--Jesse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Nov 2010 17:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-eap-tls/m-p/1459398#M312429</guid>
      <dc:creator>jedubois</dc:creator>
      <dc:date>2010-11-05T17:41:52Z</dc:date>
    </item>
  </channel>
</rss>

