<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius EAP-TLS user authentication not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156100#M1114876</link>
    <description>&lt;P&gt;PEAP ms-chap is work&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Eap-tls not work&lt;/P&gt;
&lt;P&gt;That meaning the endpoint trust server cert. But the server not trust endpoint cert.&lt;/P&gt;
&lt;P&gt;Check the CA of both cert. It must issuer from different CA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then check CA cert. In radius one CA cert. Is missing&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2024 20:00:44 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-08-05T20:00:44Z</dc:date>
    <item>
      <title>Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5154599#M1114805</link>
      <description>&lt;P&gt;Hello friends, I configured eap-tls configuration on Cisco ISE using a trusted certificate for both User and Machine for the machine that is in the domain. The machine authentication works fine, but the user authentication didn't work and didn't send anything because I don't see any log on the switch (with a "debug radius authentication) and nothing on ISE Radius logs. I tried to logout and log back in and also tried to restart the machine, but no luck. I'm using physical laptop windows 10 (22H2).&amp;nbsp;&amp;nbsp;Not sure if this is an issue on the windows or I'm missing something.&lt;/P&gt;&lt;P&gt;FYI, the user authentication is working fine with PEAP (MS-CHAp-V2).&lt;/P&gt;&lt;P&gt;Please let me know if you have any suggestion or advise ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5154599#M1114805</guid>
      <dc:creator>SecurityEng99</dc:creator>
      <dc:date>2024-08-01T14:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5154778#M1114808</link>
      <description>&lt;P&gt;Two things to check:&lt;/P&gt;
&lt;P&gt;1. How is the native supplicant configured? (Should be for "User or Computer Authentication" with single sign-on.)&lt;/P&gt;
&lt;P&gt;2. Have you checked if Microsoft Credential Guard is configured? &lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune#enable-credential-guard" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune#enable-credential-guard&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 02:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5154778#M1114808</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-02T02:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5155946#M1114862</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- yes, I tried the Machine authentication and it works fine, but when I switch to User authentication it didn't work.&lt;/P&gt;&lt;P&gt;2- I enabled the "&lt;SPAN&gt;Microsoft Credential Guard" as mentioned in the documentation guide, but it is still not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would say this is definitely a supplicant issue, but not sure about the root cause.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 13:42:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5155946#M1114862</guid>
      <dc:creator>SecurityEng99</dc:creator>
      <dc:date>2024-08-05T13:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156093#M1114874</link>
      <description>&lt;P&gt;Credential Guard will cause the native supplicant to fail. It should be disabled unless you switch to certificate-based authentication.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 19:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156093#M1114874</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-05T19:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156098#M1114875</link>
      <description>&lt;P&gt;I'm using the smartcard or certificate option. In the additional setting, I'm using the User authenticatiion.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SecurityEng99_0-1722887928128.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/225497iFF4829B36C76393F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SecurityEng99_0-1722887928128.png" alt="SecurityEng99_0-1722887928128.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 19:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156098#M1114875</guid>
      <dc:creator>SecurityEng99</dc:creator>
      <dc:date>2024-08-05T19:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156100#M1114876</link>
      <description>&lt;P&gt;PEAP ms-chap is work&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Eap-tls not work&lt;/P&gt;
&lt;P&gt;That meaning the endpoint trust server cert. But the server not trust endpoint cert.&lt;/P&gt;
&lt;P&gt;Check the CA of both cert. It must issuer from different CA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then check CA cert. In radius one CA cert. Is missing&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156100#M1114876</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-05T20:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156101#M1114877</link>
      <description>&lt;P&gt;EAP-TLS for Machine authentication works (Cert-based)&lt;/P&gt;&lt;P&gt;EAP-TLS for &lt;STRONG&gt;User&lt;/STRONG&gt; authentication is &lt;STRONG&gt;not working&lt;/STRONG&gt;&amp;nbsp; (Cert-based)&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156101#M1114877</guid>
      <dc:creator>SecurityEng99</dc:creator>
      <dc:date>2024-08-05T20:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156109#M1114878</link>
      <description>&lt;P&gt;User Cert. check the CA issuer or sub in radius server&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156109#M1114878</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-05T20:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Radius EAP-TLS user authentication not working</title>
      <link>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156353#M1114891</link>
      <description>&lt;P&gt;If you are not seeing the authentication at all in ISE, then the supplicant must not be sending it.&lt;/P&gt;
&lt;P&gt;Double check that your additional setting is using either a. User Authentication or b. User or Computer Authentication. Like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MarvinRhoads_0-1722935272283.png" style="width: 731px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/225533iA2E718EA01B9E574/image-dimensions/731x475?v=v2" width="731" height="475" role="button" title="MarvinRhoads_0-1722935272283.png" alt="MarvinRhoads_0-1722935272283.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 09:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/radius-eap-tls-user-authentication-not-working/m-p/5156353#M1114891</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-06T09:08:19Z</dc:date>
    </item>
  </channel>
</rss>

