<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic hello,,,i do confirm that , in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439357#M86539</link>
    <description>&lt;P&gt;hello,,,&lt;/P&gt;&lt;P&gt;i do confirm that , the 3rd Party already trust the AAA CA , and the AAA trust the 3rd Party CA.&lt;/P&gt;&lt;P&gt;when i use Cisco 4.1 Radius , the client is connected without any problem.&lt;/P&gt;&lt;P&gt;to clarify the status , this client accept only eap-tls authentication method ,so the only changes which i did on the 4.1 radius , is go to system configuration , global authentication setup , and enable the eap-tls only...and change the&amp;nbsp;AP EAP request timeout to 0&lt;/P&gt;&lt;P&gt;and this what i did also in ACS5.1&lt;/P&gt;&lt;P&gt;any suggestions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;reyad&lt;/P&gt;</description>
    <pubDate>Wed, 30 Apr 2014 10:44:24 GMT</pubDate>
    <dc:creator>Reyad Safi</dc:creator>
    <dc:date>2014-04-30T10:44:24Z</dc:date>
    <item>
      <title>ACS EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439353#M86535</link>
      <description>&lt;P&gt;Hello Experts...&lt;/P&gt;&lt;P&gt;i have a problem when using ACS 5.1 with AP1141 through EAP-TLS authentication method.&lt;/P&gt;&lt;P&gt;when i try to connect my laptop , it's authenticated sucessfully , but when i try to authenticate third party Black Box using EAP-TLS , i have an authentication failure (&amp;nbsp;12511 Unexpectedly received TLS alert message; treating as a rejection by the client ).&lt;/P&gt;&lt;P&gt;when i check the debug report at the ACS , i found that the authentication method when i use my laptop is&amp;nbsp;x509_PKI &amp;nbsp;, and it's successfully , but when i use the 3rd party devise , the authentication method in the radius log report is&amp;nbsp;EAP-TLS , and it's failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so is there any different between the&amp;nbsp;x509_PKI &amp;nbsp;and&amp;nbsp;EAP-TLS , if yes , how could i check EAP-TLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;reyad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439353#M86535</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2019-03-11T04:39:15Z</dc:date>
    </item>
    <item>
      <title>fyi, EAP TLS involves</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439354#M86536</link>
      <description>&lt;P&gt;fyi, EAP TLS involves exchange of certificate between client and server, where the certificate issued to client is in x.509 format , issued by CA ( part of PKI ). The below could be reason of above mentioned error&lt;/P&gt;&lt;P class="pB1_Body1"&gt;The supplicant or client machine is not accepting the certificate from Cisco ISE.The client machine is configured to validate the server certificate, but is not configured to trust the Cisco ISE certificate.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2014 03:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439354#M86536</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-04-21T03:33:49Z</dc:date>
    </item>
    <item>
      <title>thank you Saldohi install</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439355#M86537</link>
      <description>&lt;P&gt;thank you Saldoh&lt;/P&gt;&lt;P&gt;i install wireshark to get the authentications logs , and i compare this log with working ACS....&lt;/P&gt;&lt;P&gt;the only difference is EAP-TLS Flag: 0x00 ,&lt;/P&gt;&lt;P&gt;0... ... = length include false , while its true at the working one.&lt;/P&gt;&lt;P&gt;any recommendation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reyad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2014 23:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439355#M86537</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2014-04-21T23:12:20Z</dc:date>
    </item>
    <item>
      <title>As you have stated that you</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439356#M86538</link>
      <description>&lt;P&gt;As you have stated that you authentication with 3rd party device is failing it may be due to certificate issue.EAP-TLS&amp;nbsp;&lt;SPAN class="content"&gt;use certificates for both user and server authentication &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;check EAP-TLS Deployment Guide for Wireless LAN Networks&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_white_paper09186a008009256b.shtml#wp39021&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 03:29:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439356#M86538</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2014-04-22T03:29:17Z</dc:date>
    </item>
    <item>
      <title>hello,,,i do confirm that ,</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439357#M86539</link>
      <description>&lt;P&gt;hello,,,&lt;/P&gt;&lt;P&gt;i do confirm that , the 3rd Party already trust the AAA CA , and the AAA trust the 3rd Party CA.&lt;/P&gt;&lt;P&gt;when i use Cisco 4.1 Radius , the client is connected without any problem.&lt;/P&gt;&lt;P&gt;to clarify the status , this client accept only eap-tls authentication method ,so the only changes which i did on the 4.1 radius , is go to system configuration , global authentication setup , and enable the eap-tls only...and change the&amp;nbsp;AP EAP request timeout to 0&lt;/P&gt;&lt;P&gt;and this what i did also in ACS5.1&lt;/P&gt;&lt;P&gt;any suggestions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;reyad&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 10:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-eap-tls/m-p/2439357#M86539</guid>
      <dc:creator>Reyad Safi</dc:creator>
      <dc:date>2014-04-30T10:44:24Z</dc:date>
    </item>
  </channel>
</rss>

