<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP TLS- SHA 2 certificate , Thin client not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4497237#M570823</link>
    <description>&lt;P&gt;Authentication Details&lt;BR /&gt;Source Timestamp 2021-11-03 14:41:48.303&lt;BR /&gt;Received Timestamp 2021-11-03 14:41:48.303&lt;BR /&gt;Policy Server&amp;nbsp;&lt;BR /&gt;Event 5434 Endpoint conducted several failed authentications of the same scenario&lt;BR /&gt;Failure Reason 11510 Supplicant declined EAP method selected by Authentication Policy but did not propose another one; EAP negotiation failed&lt;BR /&gt;Resolution Ensure that the supplicant is correctly configured. Verify that supplicant has at least one EAP method cofigured.&lt;BR /&gt;Root cause In previous EAP message ISE started an EAP method selected by Authentication Policy. Supplicant declined this EAP method by sending EAP NAK message but did not propose another EAP method that it is ready to conduct. Owing to this, EAP-negotiation failed.&lt;BR /&gt;Username USERNAME&lt;BR /&gt;Endpoint Id F4:39:09:&lt;BR /&gt;IPv4 Address 10.1&lt;BR /&gt;Audit Session Id 0A407D100000093885F13954&lt;BR /&gt;Authentication Method dot1x&lt;BR /&gt;Service Type Framed&lt;BR /&gt;Network Device ASQ-&lt;BR /&gt;Device Type All Device Types#Switch&lt;BR /&gt;Location All Locations#1 Angel Square&lt;BR /&gt;NAS IPv4 Address 10.163.&lt;BR /&gt;NAS Port Id GigabitEthernet8/5&lt;BR /&gt;NAS Port Type Ethernet&lt;/P&gt;</description>
    <pubDate>Wed, 03 Nov 2021 15:10:29 GMT</pubDate>
    <dc:creator>anilkumar.cisco</dc:creator>
    <dc:date>2021-11-03T15:10:29Z</dc:date>
    <item>
      <title>EAP TLS- SHA 2 certificate , Thin client not working</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4497230#M570822</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;my authentication and authorization policy are correct, as SHA1 certificate is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when importing SHA2 client site certificate, I am getting Below error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event 5434 Endpoint conducted several failed authentications of the same scenario&lt;BR /&gt;Failure Reason 11510 Supplicant declined EAP method selected by Authentication Policy but did not propose another one; EAP negotiation failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In new SHA2 root certificate, I am seeing use only for Infrastructure but old SHA1 root ceritificate in Cisco ISE showing , it is for both Infra and endpoints..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls advise.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 15:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4497230#M570822</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-11-03T15:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: EAP TLS- SHA 2 certificate , Thin client not working</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4497237#M570823</link>
      <description>&lt;P&gt;Authentication Details&lt;BR /&gt;Source Timestamp 2021-11-03 14:41:48.303&lt;BR /&gt;Received Timestamp 2021-11-03 14:41:48.303&lt;BR /&gt;Policy Server&amp;nbsp;&lt;BR /&gt;Event 5434 Endpoint conducted several failed authentications of the same scenario&lt;BR /&gt;Failure Reason 11510 Supplicant declined EAP method selected by Authentication Policy but did not propose another one; EAP negotiation failed&lt;BR /&gt;Resolution Ensure that the supplicant is correctly configured. Verify that supplicant has at least one EAP method cofigured.&lt;BR /&gt;Root cause In previous EAP message ISE started an EAP method selected by Authentication Policy. Supplicant declined this EAP method by sending EAP NAK message but did not propose another EAP method that it is ready to conduct. Owing to this, EAP-negotiation failed.&lt;BR /&gt;Username USERNAME&lt;BR /&gt;Endpoint Id F4:39:09:&lt;BR /&gt;IPv4 Address 10.1&lt;BR /&gt;Audit Session Id 0A407D100000093885F13954&lt;BR /&gt;Authentication Method dot1x&lt;BR /&gt;Service Type Framed&lt;BR /&gt;Network Device ASQ-&lt;BR /&gt;Device Type All Device Types#Switch&lt;BR /&gt;Location All Locations#1 Angel Square&lt;BR /&gt;NAS IPv4 Address 10.163.&lt;BR /&gt;NAS Port Id GigabitEthernet8/5&lt;BR /&gt;NAS Port Type Ethernet&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 15:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4497237#M570823</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-11-03T15:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: EAP TLS- SHA 2 certificate , Thin client not working</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4498205#M570875</link>
      <description>&lt;P&gt;Please review&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_self"&gt;How To Implement Digital Certificates in ISE&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 05 Nov 2021 01:50:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4498205#M570875</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-11-05T01:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: EAP TLS- SHA 2 certificate , Thin client not working</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4514882#M571526</link>
      <description>&lt;P&gt;There was issue at the client site.. they were not presenting certificate properly.. and because of that.. ISE were not able to identify and validate the certificate match in AD as binary comparison..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after that correction issue resolved..&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 01:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-sha-2-certificate-thin-client-not-working/m-p/4514882#M571526</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-12-08T01:49:34Z</dc:date>
    </item>
  </channel>
</rss>

