<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I know that this thread is in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592652#M72124</link>
    <description>&lt;P&gt;I know that this thread is old but were you able to resolve this issue?&lt;/P&gt;</description>
    <pubDate>Sat, 20 Feb 2016 05:00:19 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2016-02-20T05:00:19Z</dc:date>
    <item>
      <title>12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592646#M72112</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have root CA and intermediate CA in ISE local certificate store trusted for client authentication.&lt;/P&gt;&lt;P&gt;I have imported both root ca and client certificate in the device I want to authenticate, but ISE keeps spitting out this error :&lt;/P&gt;&lt;P&gt;12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592646#M72112</guid>
      <dc:creator>bmwstoof1</dc:creator>
      <dc:date>2019-03-11T05:10:36Z</dc:date>
    </item>
    <item>
      <title>So the client is not liking</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592647#M72113</link>
      <description>&lt;P&gt;So the client is not liking something about the certificate/certificate setup. Can you tell us:&lt;/P&gt;&lt;P&gt;1. What version and patch of ISE you are running&lt;/P&gt;&lt;P&gt;2. What type of authentication you are trying to do (PEAP, EAP-TLS, etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 16:10:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592647#M72113</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-13T16:10:25Z</dc:date>
    </item>
    <item>
      <title>Refer the link for</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592648#M72115</link>
      <description>&lt;P&gt;Refer the link for troubleshooting in page no 22 the issue is mentioned, check it: &lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_81_troubleshooting_failed_authc.pdf"&gt;http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_81_troubleshooting_failed_authc.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 17:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592648#M72115</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-11-13T17:10:37Z</dc:date>
    </item>
    <item>
      <title>Hi Neno, I am running V1.2.0</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592649#M72117</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running V1.2.0.899&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advice ? thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 08:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592649#M72117</guid>
      <dc:creator>bmwstoof1</dc:creator>
      <dc:date>2014-11-18T08:35:02Z</dc:date>
    </item>
    <item>
      <title>I checked it, but what is</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592650#M72120</link>
      <description>&lt;P&gt;I checked it, but what is described as solution has already been done in my case the issue is still there.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 08:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592650#M72120</guid>
      <dc:creator>bmwstoof1</dc:creator>
      <dc:date>2014-11-18T08:36:54Z</dc:date>
    </item>
    <item>
      <title>Can you post screenshots of</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592651#M72122</link>
      <description>&lt;P&gt;Can you post screenshots of of the supplicants configuration screens?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 17:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592651#M72122</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-18T17:10:12Z</dc:date>
    </item>
    <item>
      <title>I know that this thread is</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592652#M72124</link>
      <description>&lt;P&gt;I know that this thread is old but were you able to resolve this issue?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 05:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592652#M72124</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-02-20T05:00:19Z</dc:date>
    </item>
    <item>
      <title>I was getting today the same</title>
      <link>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592653#M72126</link>
      <description>&lt;P&gt;I was getting today the same ISE authentication error when connecting Blackberry devices into the WiFi using EAP-TLS for which I have an Entrust signed cert installed on ISE running both services PEAP + EAP-TLS.&lt;/P&gt;
&lt;P&gt;After multiple troubleshooting we found the following:&lt;/P&gt;
&lt;P&gt;-The Entrust L1K intermediate cert (part of the ISE Cert chain) is not included into the BB, IPAD, Android, Win, etc CA Trusted list that comes by default with their respective OS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;SPAN style="line-height: 20px; text-indent: -18pt;"&gt;&lt;SPAN style="text-indent: -18pt;"&gt;The Entrust Root CA G2 that comes with the Blackberry OS looks like it was corrupted.&lt;/SPAN&gt;&lt;BR style="text-indent: -18pt;" /&gt;&lt;SPAN style="text-indent: -18pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="line-height: 20px; text-indent: -18pt;"&gt;Solution&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Using BB BES 12 we created a profile and pushed the Entrust L1K Cert into the BB Device Internal CA Trusted List (added it) and overwrote the Entrust G2 as well.&lt;/P&gt;
&lt;P&gt;When I initially added the L1K and tested it, I was still getting the error message on ISE so I found the following link that gave me the idea to overwrite the default Entrust Root CA G2.&lt;/P&gt;
&lt;P&gt;http://support.blackberry.com/kb/articleDetail?ArticleNumber=000036357&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 19:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/12520-eap-tls-failed-ssl-tls-handshake-because-the-client/m-p/2592653#M72126</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2016-08-24T19:28:35Z</dc:date>
    </item>
  </channel>
</rss>

