<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EAP-TLS failed SSL/TLS handshake after a client alert in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634072#M575592</link>
    <description>&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope everyone is keeping well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are in the process of deploying EAP-TLS in a pilot phase with a mix of Mac OS and Win10 machines in our estate. Currently Win10 machines are working and being authenticated to the Corporate WLAN, but Mac OS machines (not domain joined) try to connect, we are getting 50/50 split of passed/failed authentications, no changes are being made to either ISE or the Mac (managed by JAMF).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Passed Auth -&amp;nbsp;Event&amp;nbsp;5200 Authentication succeeded&lt;/P&gt;&lt;P&gt;Failed Auth -&amp;nbsp;Event&amp;nbsp;5400 Authentication failed (&amp;nbsp;Failure Reason&amp;nbsp;12521 EAP-TLS failed SSL/TLS handshake after a client alert )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the Mac is not accepting the EAP-TLS handshake with ISE and failing with the following result in ISE logs:&lt;BR /&gt;12815 Extracted TLS Alert message&lt;BR /&gt;12521 EAP-TLS failed SSL/TLS handshake after a client alert&lt;BR /&gt;12507 EAP-TLS authentication failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you see in ISE what certificate is being sent as part of the EAP-TLS request, or if anyone has managed to get Mac OS machine working using EAP-TLS? I have seen a couple of forum posts mentioning about creating a 2nd SSID for Mac's, but not sure if this then is keep going forward with you then managing 2x SSID's for Win &amp;amp; Mac OS machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jun 2022 07:30:23 GMT</pubDate>
    <dc:creator>JAMES WEST</dc:creator>
    <dc:date>2022-06-18T07:30:23Z</dc:date>
    <item>
      <title>EAP-TLS failed SSL/TLS handshake after a client alert</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634072#M575592</link>
      <description>&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope everyone is keeping well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are in the process of deploying EAP-TLS in a pilot phase with a mix of Mac OS and Win10 machines in our estate. Currently Win10 machines are working and being authenticated to the Corporate WLAN, but Mac OS machines (not domain joined) try to connect, we are getting 50/50 split of passed/failed authentications, no changes are being made to either ISE or the Mac (managed by JAMF).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Passed Auth -&amp;nbsp;Event&amp;nbsp;5200 Authentication succeeded&lt;/P&gt;&lt;P&gt;Failed Auth -&amp;nbsp;Event&amp;nbsp;5400 Authentication failed (&amp;nbsp;Failure Reason&amp;nbsp;12521 EAP-TLS failed SSL/TLS handshake after a client alert )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the Mac is not accepting the EAP-TLS handshake with ISE and failing with the following result in ISE logs:&lt;BR /&gt;12815 Extracted TLS Alert message&lt;BR /&gt;12521 EAP-TLS failed SSL/TLS handshake after a client alert&lt;BR /&gt;12507 EAP-TLS authentication failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you see in ISE what certificate is being sent as part of the EAP-TLS request, or if anyone has managed to get Mac OS machine working using EAP-TLS? I have seen a couple of forum posts mentioning about creating a 2nd SSID for Mac's, but not sure if this then is keep going forward with you then managing 2x SSID's for Win &amp;amp; Mac OS machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2022 07:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634072#M575592</guid>
      <dc:creator>JAMES WEST</dc:creator>
      <dc:date>2022-06-18T07:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS failed SSL/TLS handshake after a client alert</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634084#M575593</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check this thread :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/eap-tls-issue/td-p/3545371" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/eap-tls-issue/td-p/3545371&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2022 08:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634084#M575593</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-06-18T08:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS failed SSL/TLS handshake after a client alert</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634399#M575598</link>
      <description>&lt;P&gt;Hi James&lt;/P&gt;
&lt;P&gt;In ISE after the process of sucess AuthorZ you can see the serial number of certificate's template&amp;nbsp; (when endpoint use TLS together with ISE). In mi experience, Mac work better with PEAP. You can add PEAP+Mac Address Internal (On ISE) to consolidate the access.&lt;/P&gt;
&lt;P&gt;Regards, Ivan.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 02:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-failed-ssl-tls-handshake-after-a-client-alert/m-p/4634399#M575598</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2022-06-19T02:23:47Z</dc:date>
    </item>
  </channel>
</rss>

