<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ise certificate validation failed in log in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167256#M563328</link>
    <description>&lt;P&gt;hello cisco community,&lt;/P&gt;&lt;P&gt;I have problem in eap tls and I searching the log in every device to solve the problem.&lt;/P&gt;&lt;P&gt;when I look to wlc, wlc generate log like this :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;RADIUS server 10.175.4.71:1812 failed to respond to request (ID 79) for client f8:94:c2:1a:22:a5 / user 'bbb@aaa.com'&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and in ISE generate some log, but there is significant log that I think the problem :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;34151 WARN System-Management: Certificate Validation Failed, ConfigVersionId=109, AdminName=Unknown, OperationMessageText=Certificate Validation failed for host:ise.aaa.com, AcsInstance=ise.aaa.com,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my question are :&lt;/P&gt;&lt;P&gt;1. is there any chance the eap-tls not success because certificate in ise (like log said, certificate validation is failed)??&lt;/P&gt;&lt;P&gt;2. I dont see any explanation about that log. would somebody care to explain what I must to do for fixing the log in ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2020 06:48:28 GMT</pubDate>
    <dc:creator>Abreey</dc:creator>
    <dc:date>2020-10-15T06:48:28Z</dc:date>
    <item>
      <title>ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167256#M563328</link>
      <description>&lt;P&gt;hello cisco community,&lt;/P&gt;&lt;P&gt;I have problem in eap tls and I searching the log in every device to solve the problem.&lt;/P&gt;&lt;P&gt;when I look to wlc, wlc generate log like this :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;RADIUS server 10.175.4.71:1812 failed to respond to request (ID 79) for client f8:94:c2:1a:22:a5 / user 'bbb@aaa.com'&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and in ISE generate some log, but there is significant log that I think the problem :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;34151 WARN System-Management: Certificate Validation Failed, ConfigVersionId=109, AdminName=Unknown, OperationMessageText=Certificate Validation failed for host:ise.aaa.com, AcsInstance=ise.aaa.com,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my question are :&lt;/P&gt;&lt;P&gt;1. is there any chance the eap-tls not success because certificate in ise (like log said, certificate validation is failed)??&lt;/P&gt;&lt;P&gt;2. I dont see any explanation about that log. would somebody care to explain what I must to do for fixing the log in ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 06:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167256#M563328</guid>
      <dc:creator>Abreey</dc:creator>
      <dc:date>2020-10-15T06:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167415#M563337</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;what do u have in authentication details for this endpoint? can u see 12321 "failed SSL/TLS"?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 11:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167415#M563337</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2020-10-15T11:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167455#M563339</link>
      <description>&lt;P&gt;thank you andy for respon,&lt;/P&gt;&lt;P&gt;there is no 12321 "failed SSL/TLS" in ise log.&lt;/P&gt;&lt;P&gt;like picture below, only code 5440 endpoint abandoned EAP session and started new.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eaptls-community cisco.png" style="width: 864px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86029iFCA815E192F837B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="eaptls-community cisco.png" alt="eaptls-community cisco.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eap-tls handshake-community cisco.jpg" style="width: 453px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86030i9CBB34B039936560/image-size/large?v=v2&amp;amp;px=999" role="button" title="eap-tls handshake-community cisco.jpg" alt="eap-tls handshake-community cisco.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I did tcpdump in ISE interface and there is no step 7 to 10 (like picture below) at my pcap file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 11:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167455#M563339</guid>
      <dc:creator>Abreey</dc:creator>
      <dc:date>2020-10-15T11:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167653#M563348</link>
      <description>&lt;P&gt;How the endpoint's NIC is configured for dot1x?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 15:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167653#M563348</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-15T15:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167889#M563356</link>
      <description>&lt;P&gt;Hi Aref, thank you for reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;like picture below, I configured endpoint nic using certificate's user. certificate's user deploy using GPO auto enroll and signed using ENT-CA. ENT-CA and ROOT-CA already in trusted certificates at ISE and endpoint.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certificated-cisco community.PNG" style="width: 516px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86092iF55DB55785ECADF4/image-size/large?v=v2&amp;amp;px=999" role="button" title="certificated-cisco community.PNG" alt="certificated-cisco community.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wifi_801x-user authentication.PNG" style="width: 436px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86090i2CDCA130CA712429/image-size/large?v=v2&amp;amp;px=999" role="button" title="wifi_801x-user authentication.PNG" alt="wifi_801x-user authentication.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wifi_configuration-cisco community.PNG" style="width: 439px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86091iBCEF5399F088844F/image-size/large?v=v2&amp;amp;px=999" role="button" title="wifi_configuration-cisco community.PNG" alt="wifi_configuration-cisco community.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 01:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167889#M563356</guid>
      <dc:creator>Abreey</dc:creator>
      <dc:date>2020-10-16T01:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167892#M563358</link>
      <description>&lt;P&gt;If the client supplicant is not sending its certificate chain in response to the server (ISE) certificate, it is likely not trusting the ISE EAP cert and terminating the EAP connection.&lt;/P&gt;
&lt;P&gt;I would suggest reviewing the following documents and comparing to your environment:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html" target="_blank" rel="noopener"&gt;Understand and configure EAP-TLS using WLC and ISE&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html#anc27" target="_blank" rel="noopener"&gt;Configure EAP-TLS Authentication with ISE - Common Issues and Techniques to Troubleshoot&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is also a similar Community post &lt;A href="https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/td-p/4095569" target="_blank" rel="noopener"&gt;here&lt;/A&gt; that might provide some guidance. These certificate issues can be tricky to troubleshoot without experience, so you might need to open a TAC case to investigate further.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 01:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4167892#M563358</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-10-16T01:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: ise certificate validation failed in log</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4170024#M563417</link>
      <description>&lt;P&gt;Thank you Greg for the answer.&lt;/P&gt;&lt;P&gt;I will call TAC soon for investigate the wlc one. because I create lab with same ise and key chain in wired 802.1x environment it works like a charms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 06:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-certificate-validation-failed-in-log/m-p/4170024#M563417</guid>
      <dc:creator>Abreey</dc:creator>
      <dc:date>2020-10-20T06:53:46Z</dc:date>
    </item>
  </channel>
</rss>

