<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wired EAP-TLS Problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765955#M419784</link>
    <description>&lt;P&gt;I'm trying to setup wired clients to authenticate with EAP-TLS on a Catalyst 2950, I put together a test setup using the configs on my freeRADIUS server taken from another which is working with EAP-TLS over wireless, the requests are being passed through to the server but the authentication is still failing, could anyone give me some advice?  Logs and configs included below......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current setup is:&lt;/P&gt;&lt;P&gt;FreeRADIUS server - Fedora Core 6, freeradius-1.1.3-2.fc6, freeradius-mysql-1.1.3-2.fc6&lt;/P&gt;&lt;P&gt;Cisco Catalyst 2950 - IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(22)EA9, RELEASE SOFTWARE (fc1) - c2950-i6q4l2-mz.121-22.EA9.bin&lt;/P&gt;&lt;P&gt;Laptop - OpenSUSE 10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed the guide to setting up 802.1x auth on the switch from the 2950 docs and from here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO" target="_blank"&gt;http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO&lt;/A&gt; (although I'm not using Windows, so only the switch config is relevant)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"select * from nas" (comma seperated to make it easier):&lt;/P&gt;&lt;P&gt;id,nasname,shortname,type,ports,secret,community,description&lt;/P&gt;&lt;P&gt;1,10.10.0.9/32,Catalyst,cisco,NULL,&amp;lt;secret&amp;gt;,NULL Catalyst 2950&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wpa_supplicant.conf on laptop:&lt;/P&gt;&lt;P&gt;ctrl_interface=/var/run/wpa_supplicant&lt;/P&gt;&lt;P&gt;ctrl_interface_group=wheel&lt;/P&gt;&lt;P&gt;ap_scan=0&lt;/P&gt;&lt;P&gt;network={&lt;/P&gt;&lt;P&gt;   key_mgmt=IEEE8021X&lt;/P&gt;&lt;P&gt;   identity="SUSE Laptop"&lt;/P&gt;&lt;P&gt;   eapol_flags=0&lt;/P&gt;&lt;P&gt;   eap=TLS&lt;/P&gt;&lt;P&gt;   ca_cert="/home/evosys/Documents/cacert.pem"&lt;/P&gt;&lt;P&gt;   client_cert="/home/evosys/Documents/suse_cert.pem"&lt;/P&gt;&lt;P&gt;   private_key="/home/evosys/Documents/suse_key.pem"&lt;/P&gt;&lt;P&gt;   private_key_passwd="&amp;lt;password&amp;gt;"&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outputs of the radiusd and wpa_supplicant are attached...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:19:50 GMT</pubDate>
    <dc:creator>darren_maden</dc:creator>
    <dc:date>2019-03-10T22:19:50Z</dc:date>
    <item>
      <title>Wired EAP-TLS Problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765955#M419784</link>
      <description>&lt;P&gt;I'm trying to setup wired clients to authenticate with EAP-TLS on a Catalyst 2950, I put together a test setup using the configs on my freeRADIUS server taken from another which is working with EAP-TLS over wireless, the requests are being passed through to the server but the authentication is still failing, could anyone give me some advice?  Logs and configs included below......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current setup is:&lt;/P&gt;&lt;P&gt;FreeRADIUS server - Fedora Core 6, freeradius-1.1.3-2.fc6, freeradius-mysql-1.1.3-2.fc6&lt;/P&gt;&lt;P&gt;Cisco Catalyst 2950 - IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(22)EA9, RELEASE SOFTWARE (fc1) - c2950-i6q4l2-mz.121-22.EA9.bin&lt;/P&gt;&lt;P&gt;Laptop - OpenSUSE 10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed the guide to setting up 802.1x auth on the switch from the 2950 docs and from here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO" target="_blank"&gt;http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO&lt;/A&gt; (although I'm not using Windows, so only the switch config is relevant)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"select * from nas" (comma seperated to make it easier):&lt;/P&gt;&lt;P&gt;id,nasname,shortname,type,ports,secret,community,description&lt;/P&gt;&lt;P&gt;1,10.10.0.9/32,Catalyst,cisco,NULL,&amp;lt;secret&amp;gt;,NULL Catalyst 2950&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wpa_supplicant.conf on laptop:&lt;/P&gt;&lt;P&gt;ctrl_interface=/var/run/wpa_supplicant&lt;/P&gt;&lt;P&gt;ctrl_interface_group=wheel&lt;/P&gt;&lt;P&gt;ap_scan=0&lt;/P&gt;&lt;P&gt;network={&lt;/P&gt;&lt;P&gt;   key_mgmt=IEEE8021X&lt;/P&gt;&lt;P&gt;   identity="SUSE Laptop"&lt;/P&gt;&lt;P&gt;   eapol_flags=0&lt;/P&gt;&lt;P&gt;   eap=TLS&lt;/P&gt;&lt;P&gt;   ca_cert="/home/evosys/Documents/cacert.pem"&lt;/P&gt;&lt;P&gt;   client_cert="/home/evosys/Documents/suse_cert.pem"&lt;/P&gt;&lt;P&gt;   private_key="/home/evosys/Documents/suse_key.pem"&lt;/P&gt;&lt;P&gt;   private_key_passwd="&amp;lt;password&amp;gt;"&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outputs of the radiusd and wpa_supplicant are attached...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765955#M419784</guid>
      <dc:creator>darren_maden</dc:creator>
      <dc:date>2019-03-10T22:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Wired EAP-TLS Problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765956#M419788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Based on this:&lt;/P&gt;&lt;P&gt;TLS: Certificate verification failed, error 19 (self signed certificate in certificate chain) &lt;/P&gt;&lt;P&gt;SSL: SSL3 alert: write (local SSL3 detected an error):fatal:unknown CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say that your freeRADIUS server is providing a self-signed cert and the supplicant doesn't trust the signature.  The client's ca_cert has to be the same one that signed the freeRADIUS server's cert (or you have to disable certificate verification on the client).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2007 14:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765956#M419788</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2007-08-13T14:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wired EAP-TLS Problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765957#M419791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The link you provided explains about PEAP authentication and you want set up EAP-TLS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For TLS you need three certs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CA&lt;/P&gt;&lt;P&gt;Server cert&lt;/P&gt;&lt;P&gt;Client cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2007 19:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765957#M419791</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-08-13T19:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Wired EAP-TLS Problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765958#M419793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Creating a new CA for testing solved the problem, I've obviously had a mix up somewhere in my certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've now got EAP-TLS working for wired clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing was needed on the switch that isn't in it's documentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2007 08:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/765958#M419793</guid>
      <dc:creator>darren_maden</dc:creator>
      <dc:date>2007-08-14T08:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wired EAP-TLS Problems</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/3221178#M419795</link>
      <description>&lt;P&gt;Hi Darren&lt;/P&gt;
&lt;P&gt;I am facing the&amp;nbsp;same problem. My setup consists of ubuntu box with wpa_supplicant which connects to SDN controller, which in turn talks to RADIUS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have generated certificates multiple times but issue not resolved. Can you share the steps of generating certs for server and the client?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Thanks&lt;/P&gt;
&lt;P&gt;Jahangir&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 18:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-eap-tls-problems/m-p/3221178#M419795</guid>
      <dc:creator>mohd_jahangir</dc:creator>
      <dc:date>2017-11-22T18:43:45Z</dc:date>
    </item>
  </channel>
</rss>

