<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UPN username format fails using EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954436#M384954</link>
    <description>&lt;P&gt;We deployed ACS 4.0 (NOT ACS SE) and WLAN in our corporate network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our ultimate goal is to have each staff authenticated against our AD via ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We managed to get PEAP working successfully, but failed with EAP-TLS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the log we noticed that when PEAP is used, ACS forward username to AD in domain-qualified format (domain\user),and authentication is successful. &lt;/P&gt;&lt;P&gt;When EAP-TLS is used, ACS forward username to AD in UPN format (user@domain), and ACS received "cannot get user account controler for user@domain" from windows database, authentication failed. Any workaround for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone throw some light here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Lahki&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:58:17 GMT</pubDate>
    <dc:creator>Lucky8888</dc:creator>
    <dc:date>2019-03-10T22:58:17Z</dc:date>
    <item>
      <title>UPN username format fails using EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954436#M384954</link>
      <description>&lt;P&gt;We deployed ACS 4.0 (NOT ACS SE) and WLAN in our corporate network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our ultimate goal is to have each staff authenticated against our AD via ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We managed to get PEAP working successfully, but failed with EAP-TLS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the log we noticed that when PEAP is used, ACS forward username to AD in domain-qualified format (domain\user),and authentication is successful. &lt;/P&gt;&lt;P&gt;When EAP-TLS is used, ACS forward username to AD in UPN format (user@domain), and ACS received "cannot get user account controler for user@domain" from windows database, authentication failed. Any workaround for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone throw some light here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Lahki&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954436#M384954</guid>
      <dc:creator>Lucky8888</dc:creator>
      <dc:date>2019-03-10T22:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: UPN username format fails using EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954437#M384964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What supplicant are you using?  If you can configure it to send the EAP outer-id in a different format (e.g. just "username" or even "anonymous"), then you should avoid this problem.  Otherwise, you'll probably need to upgrade to ACS 4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jul 2008 15:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954437#M384964</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2008-07-14T15:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: UPN username format fails using EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954438#M384969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using Trapeze wirelesss gears.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2008 03:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954438#M384969</guid>
      <dc:creator>Lucky8888</dc:creator>
      <dc:date>2008-07-15T03:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: UPN username format fails using EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954439#M384977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, but your PC still has to have a supplicant.  If there's no way to change the format of the EAP outer-id in your supplicant, you'll need to upgrade your ACS.  If you have access to bug toolkit, look up CSCsk49811.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2008 15:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954439#M384977</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2008-07-15T15:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: UPN username format fails using EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954440#M384992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what you mean by supplicant. &lt;/P&gt;&lt;P&gt;All the laptops are running XP. Is it possible to change the outer-id for XP supplicant? How?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2008 22:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954440#M384992</guid>
      <dc:creator>Lucky8888</dc:creator>
      <dc:date>2008-07-15T22:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: UPN username format fails using EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954441#M385015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is solved.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/ts/fn/200/fn20228.html" target="_blank"&gt;http://www.cisco.com/en/US/ts/fn/200/fn20228.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Lahki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Jul 2008 22:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upn-username-format-fails-using-eap-tls/m-p/954441#M385015</guid>
      <dc:creator>Lucky8888</dc:creator>
      <dc:date>2008-07-20T22:50:46Z</dc:date>
    </item>
  </channel>
</rss>

