<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Suddenly started rejecting dot1x EAP-TLS authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046693#M588277</link>
    <description>&lt;P&gt;&amp;nbsp;i would cross check again certs are correct they are in certificate store and end user also have certs&lt;/P&gt;
&lt;P&gt;also post complete log from ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2024 13:46:52 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-03-21T13:46:52Z</dc:date>
    <item>
      <title>Cisco ISE Suddenly started rejecting dot1x EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046668#M588276</link>
      <description>&lt;P&gt;I recently swapped the certificate in use for EAP, RADIUS and Admin on our ISE deployment, signed using our internal CA.&amp;nbsp; &amp;nbsp;This was carried out approx 36 hours ago , application was restarted on both nodes and everything has been working fine up until now.&amp;nbsp; Then suddenly all the network clients on our LAN started failing to authenticate using Dot1X / EAP-TLS this morning.&amp;nbsp; I don't understand, is there some kind of delay in the new certificate becoming active, why fail 36 hours later!?&amp;nbsp; As far as I can see there is nothing wrong with the new certificates and internal CA root and sub certificates are all well in date.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;5400 Authentication failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;12508 EAP-TLS handshake failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anybody hit something similar?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 13:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046668#M588276</guid>
      <dc:creator>davemiddlewick</dc:creator>
      <dc:date>2024-03-21T13:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Suddenly started rejecting dot1x EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046693#M588277</link>
      <description>&lt;P&gt;&amp;nbsp;i would cross check again certs are correct they are in certificate store and end user also have certs&lt;/P&gt;
&lt;P&gt;also post complete log from ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 13:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046693#M588277</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-03-21T13:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Suddenly started rejecting dot1x EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046751#M588278</link>
      <description>&lt;P&gt;When you import a new cert on ISE and the services are restarted that cert is active and ready for use. If you are not hitting a bug the only thing comes to my mind would be related to any GPO policies that maybe have been pushed to the clients that changed the supplicant settings? or maybe you changed the security settings in ISE by removing some protocols that could be used by the clients such as TLS1.1 and SHA1? if not, I would raise this with Cisco TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 14:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046751#M588278</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-03-21T14:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Suddenly started rejecting dot1x EAP-TLS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046756#M588279</link>
      <description>&lt;P&gt;To troubleshoot EAP-TLS handshake failed you can perform packet capture on an authenticating client (as well as from the applicable PSN). Wireshark is quite good at showing you the steps in an EAP-TLS handshake and the error message in the decode usually pinpoints the failed parameter.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 14:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-suddenly-started-rejecting-dot1x-eap-tls/m-p/5046756#M588279</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-03-21T14:37:37Z</dc:date>
    </item>
  </channel>
</rss>

