<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3687533#M509051</link>
    <description>&lt;P&gt;Hello Nidihi&lt;/P&gt;
&lt;P&gt;I am having same issue and error message.&lt;/P&gt;
&lt;P&gt;My client configuration file on Win7 is one more sub-folder:&lt;/P&gt;
&lt;P&gt;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network &lt;BR /&gt;Access Manager\&lt;FONT size="3" color="#FF0000"&gt;&lt;STRONG&gt;system\&lt;/STRONG&gt;&lt;/FONT&gt;configuration.xml&lt;/P&gt;
&lt;P&gt;Is the above path correct?&lt;/P&gt;
&lt;P&gt;BTW, the sub-folder &lt;FONT size="3" color="#FF0000"&gt;\newConfigFiles is empty.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" color="#000000"&gt;Please advise which folder the client configuration file should be.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" color="#000000"&gt;Thanks.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" color="#000000"&gt;Richard&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Aug 2018 21:36:44 GMT</pubDate>
    <dc:creator>Richard Lu</dc:creator>
    <dc:date>2018-08-13T21:36:44Z</dc:date>
    <item>
      <title>12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492694#M509044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;Using windowns 802.1x suppliant in Cisco switch and Cisco wireless scenario. It works fine.&lt;/LI&gt;&lt;LI&gt;Using Anyconnect NAM, it can work in Wireless scenario but failed in wired scenario.&lt;/LI&gt;&lt;LI&gt;Using Anyconnect NAM with Cisco switch. User CAN NOT&amp;nbsp; login. ISE log said “&lt;SPAN style="font-size: 12pt; font-family: 宋体; color: red;"&gt;12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate&lt;/SPAN&gt;“.&amp;nbsp; no any invalide certificate waring message popped up.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000;"&gt;ISE version is 2.3.0.298 , anyconnect version is 4.6.01098 pre-deploy package and we tried 4.5.05030. We tried in two win7 and one win10, same issue.&lt;/P&gt;&lt;P style="color: #000000;"&gt;&lt;/P&gt;&lt;P style="color: #000000;"&gt;Any suggestion will be very appreciated!&lt;/P&gt;&lt;P style="color: #000000;"&gt;&lt;/P&gt;&lt;P style="color: #000000;"&gt;Thanks&lt;/P&gt;&lt;P style="color: #000000;"&gt;DL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 14:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492694#M509044</guid>
      <dc:creator>yongwli</dc:creator>
      <dc:date>2018-06-13T14:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492695#M509045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My initial analysis&amp;nbsp; would be to check the configuration file using profile editor and make sure you have the appropriate settings. Can you please attach the configuration file which I can check&amp;nbsp; ? also , Please raise a TAC case to troubleshoot .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 15:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492695#M509045</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-06-13T15:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492696#M509046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Nidhi... please check whether the option enabled [ V ] Validate Server Identity&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-06-13 at 7.26.32 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/117650_Screen Shot 2018-06-13 at 7.26.32 PM.png" style="height: 496px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 02:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492696#M509046</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-14T02:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492697#M509047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi hslai,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I created a NAM.xml profile for anyconnect . It should put in &lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;%ProgramData%\Cisco\ Cisco AnyConnect Secure Mobility Client\NetworkAccessManager\newConfigFiles, right? And what name should it change to for &lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 14px;"&gt;AnyConnect can recognize and use it?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 04:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492697#M509047</guid>
      <dc:creator>wenzeng</dc:creator>
      <dc:date>2018-06-14T04:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492698#M509048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will have to rename it to configuration.xml and put it in c:/program data/cisco/cisco Anyconect secure mobility client/network access manager&amp;nbsp; . and reinitialize the connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 04:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492698#M509048</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-06-14T04:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492699#M509049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Forgot to mention that Program data should be a hidden folder . So please change the settings to view the advance folder .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 15:32:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492699#M509049</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-06-14T15:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492700#M509050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With %programdata% in the address bar of the windows explorer would also take us there.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="117660" alt="Screen Shot 2018-06-14 at 8.40.46 AM.png" class="image-1 jive-image" height="102" src="/legacyfs/online/fusion/117660_Screen Shot 2018-06-14 at 8.40.46 AM.png" style="height: 101.56774193548388px; width: 346px;" width="346" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 15:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3492700#M509050</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-14T15:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3687533#M509051</link>
      <description>&lt;P&gt;Hello Nidihi&lt;/P&gt;
&lt;P&gt;I am having same issue and error message.&lt;/P&gt;
&lt;P&gt;My client configuration file on Win7 is one more sub-folder:&lt;/P&gt;
&lt;P&gt;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network &lt;BR /&gt;Access Manager\&lt;FONT size="3" color="#FF0000"&gt;&lt;STRONG&gt;system\&lt;/STRONG&gt;&lt;/FONT&gt;configuration.xml&lt;/P&gt;
&lt;P&gt;Is the above path correct?&lt;/P&gt;
&lt;P&gt;BTW, the sub-folder &lt;FONT size="3" color="#FF0000"&gt;\newConfigFiles is empty.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" color="#000000"&gt;Please advise which folder the client configuration file should be.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" color="#000000"&gt;Thanks.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" color="#000000"&gt;Richard&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 21:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3687533#M509051</guid>
      <dc:creator>Richard Lu</dc:creator>
      <dc:date>2018-08-13T21:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3687538#M509052</link>
      <description>Hi hslai&lt;BR /&gt;I am having same issue and same error message.  ISE 2.3.0298 with our internal MS PKI cert. Do you mind advise how did you fix it? Best regards.   Richard</description>
      <pubDate>Mon, 13 Aug 2018 21:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3687538#M509052</guid>
      <dc:creator>Richard Lu</dc:creator>
      <dc:date>2018-08-13T21:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3699807#M509053</link>
      <description>&lt;P&gt;Creating a NAM profile and disable server validation in the profile.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 15:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3699807#M509053</guid>
      <dc:creator>yongwli</dc:creator>
      <dc:date>2018-09-03T15:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: 12153 EAP-FAST failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3997228#M509054</link>
      <description>i had the same problem &amp;amp; exactly the same massage and when i disable server validation identity check box it works immediately and work fine.&lt;BR /&gt;Thanks alot</description>
      <pubDate>Wed, 11 Dec 2019 14:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12153-eap-fast-failed-ssl-tls-handshake-because-the-client/m-p/3997228#M509054</guid>
      <dc:creator>Ali mosbah Abdo</dc:creator>
      <dc:date>2019-12-11T14:46:07Z</dc:date>
    </item>
  </channel>
</rss>

