<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Cert in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503863#M377747</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;This happens when we are missing some kind of certificate on the ACS. As you stated that you have installed the certificates and still you are &lt;BR /&gt;getting this error.&lt;BR /&gt;&lt;BR /&gt;Most of the times I came across this error message when we don't have CA or Intermediate&lt;BR /&gt;certificate installed on the ACS certificate store.&lt;BR /&gt;&lt;BR /&gt;Make sure that you have checked the certificate under certificate trust list. Also, restart the acs services and then try.&lt;BR /&gt;&lt;BR /&gt;Regds,&lt;BR /&gt;JK&lt;BR /&gt;&lt;BR /&gt;Do rate helpful posts&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Jun 2010 01:40:55 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2010-06-16T01:40:55Z</dc:date>
    <item>
      <title>ACS Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503862#M377745</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a hard time getting my cert to work right on the ACS for PEAP. I have acs 4.2 se.&amp;nbsp; I have a 3rd party .pem. certificate&lt;/P&gt;&lt;P&gt; I have loaded it into the install acs cert as the cert file and private key. I have also loaded into the authority setup, but after the reboot when I try to enable peap and eap-tls I get this error Failed to initialize PEAP or EAP-TLS authentication protocol because ACS certificate is not installed. I am not real knowledgeable about certificates so I am sure it is something simple I am doing wrong. Please help! Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503862#M377745</guid>
      <dc:creator>kirbus_inc</dc:creator>
      <dc:date>2019-03-11T00:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503863#M377747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;This happens when we are missing some kind of certificate on the ACS. As you stated that you have installed the certificates and still you are &lt;BR /&gt;getting this error.&lt;BR /&gt;&lt;BR /&gt;Most of the times I came across this error message when we don't have CA or Intermediate&lt;BR /&gt;certificate installed on the ACS certificate store.&lt;BR /&gt;&lt;BR /&gt;Make sure that you have checked the certificate under certificate trust list. Also, restart the acs services and then try.&lt;BR /&gt;&lt;BR /&gt;Regds,&lt;BR /&gt;JK&lt;BR /&gt;&lt;BR /&gt;Do rate helpful posts&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 01:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503863#M377747</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-06-16T01:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503864#M377749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I have gotten that part to work now because it lets me enable EAP. However on my wireless client&lt;/P&gt;&lt;P&gt;it gives an error of Could not authenticate. Int he log it says authentication failed&lt;/P&gt;&lt;P&gt;during SSL handshake&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 15:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503864#M377749</guid>
      <dc:creator>kirbus_inc</dc:creator>
      <dc:date>2010-06-16T15:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503865#M377753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Well, this error message says that there is certicate missing in the chain. Please check and make sure that you have full cert chain installed on theACS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;BTW. what eap type you are using?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Also, do we have validate server certificate option checked on the client side? If it is, please uncheck that option and try again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Do rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 16:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503865#M377753</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-06-16T16:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Cert</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503866#M377754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what I have selected under Global Authentication Setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PEAP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow Posture Validation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PEAP session timeout (minutes) 120&lt;/P&gt;&lt;P&gt;Enable Fast Reconnect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow EAP-TLS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate CN Comparison&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use Outer Identity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEAP allow Leap (for Aironet only)&lt;/P&gt;&lt;P&gt;EAP-MD5 (Allow EAP-MD5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MS-CHAP config&lt;/P&gt;&lt;P&gt;Allow ms-chapv1 authentication&lt;/P&gt;&lt;P&gt;Allow ms-chapv2 authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the client under wireless properties&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network Authentication is Open&lt;/P&gt;&lt;P&gt;Data Encryption is WEP&lt;/P&gt;&lt;P&gt;check is key is provided for me authomatically&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the authenticaiton tab I have enable 1EEE 802.1x authentication network access for this network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had EAP type as smart card or certificate and have had vaildate server cert check and unchecked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also selected Protected EAP (PEAP) instead of smart card or certificate and get a ssl handshake error on te acs logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 16:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-cert/m-p/1503866#M377754</guid>
      <dc:creator>kirbus_inc</dc:creator>
      <dc:date>2010-06-16T16:30:49Z</dc:date>
    </item>
  </channel>
</rss>

