<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CAPWAP AP 802.1x supplicant with EAP-TLS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4019892#M10504</link>
    <description>&lt;P&gt;Depending on what WLC version you are running the only 802.1x auth for the AP to the network is EAP-FAST.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Prior to rel 8.7, AP port 802.1x only supported EAP-FAST, in rel 8.7 the AP supplicant will also support EAP-TLS / EAP-PEAP&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2020 21:59:24 GMT</pubDate>
    <dc:creator>Haydn Andrews</dc:creator>
    <dc:date>2020-01-28T21:59:24Z</dc:date>
    <item>
      <title>CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4019874#M10503</link>
      <description>&lt;P&gt;Hello Community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a highly secure environment with NAC on switchports. We need APs to use pre-provisioned(during staging) LSC certificates (same for DTLS encryption and AP Auth on the WLC) during 802.1x EAP-TLS authentication on the NAC switchports. We had already chained WLC with root CA and provisioned LSC certs to all APs as "802.1x + CAPWAP-DTLS". APs are using LSC certs for both CAPWAP Data and Control DTLS encryption. NAC is not enabled on the switch ports to which APs are connected yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is when we try enable "802.1x Authentication" in "802.1x Supplicant Credentials" as EAP-TLS in Access Points Global configuration in GUI, the &lt;A href="https://www.cisco.com/c/dam/en/us/td/i/400001-500000/420001-430000/425001-426000/425938.tif/_jcr_content/renditions/425938.jpg" target="_self"&gt;WLC asking for username and password.&amp;nbsp;&lt;/A&gt;(The picture is from the configuration guide).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's confusing, since we intend to use EAP-TLS which require certificate instead of credentials. &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html" target="_self"&gt;Configuration guides&lt;/A&gt; referred to this feature says: "&lt;SPAN&gt;Also configure user name and password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What will those username/password be?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 18:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4019874#M10503</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2021-07-05T18:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4019892#M10504</link>
      <description>&lt;P&gt;Depending on what WLC version you are running the only 802.1x auth for the AP to the network is EAP-FAST.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-7/b_802_1x_eap_supplicant_on_cos_ap.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Prior to rel 8.7, AP port 802.1x only supported EAP-FAST, in rel 8.7 the AP supplicant will also support EAP-TLS / EAP-PEAP&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 21:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4019892#M10504</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2020-01-28T21:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4020100#M10505</link>
      <description>&lt;P&gt;Thanks for you reply!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's 8.10.105, so this feature is supported, and we have an option to choose EAP-TLS as authentication method. We just still being asked for a username and password when we choose it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 08:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4020100#M10505</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-01-29T08:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4022864#M10506</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;When I try to enable 802.1x Authentication:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/66418i745BF210D2425D80/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get this error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 518px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/66419i7E47770C3D2F32F7/image-dimensions/518x178?v=v2" width="518" height="178" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's Global 802.1x Username? I want to use EAP-TLS...&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 17:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4022864#M10506</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-02-03T17:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4180187#M10507</link>
      <description>&lt;P&gt;Hello Murinos,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you figure out how to solve this ? If you configure EAP-TLS without any username/password set, is it working ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AL&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 22:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4180187#M10507</guid>
      <dc:creator>aleopoldie</dc:creator>
      <dc:date>2020-11-06T22:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4180475#M10508</link>
      <description>&lt;P&gt;Hello aleopoldie,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, we bumped to another problem. The ISE we use as AAA server for NAC can't trust the Root CA we use for SCEP on WLC. So, it will not accept certificates we issue for APs for EAP-TLS.&lt;/P&gt;&lt;P&gt;We are bound with EAP-FAST (login/pass) and mac check.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 10:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4180475#M10508</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-11-08T10:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4531464#M237099</link>
      <description>&lt;P&gt;Bump ? - Any news on this , we are all holding our collective breaths in anticipation &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 10:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4531464#M237099</guid>
      <dc:creator>Thomas Obbekaer Thomsen</dc:creator>
      <dc:date>2022-01-14T10:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4549529#M238265</link>
      <description>&lt;P&gt;Unfortunately, no.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were not allowed to power on 'main' root CA which is used for all production networking infrastructure. The 'additional' root CA which is used for SCEP on WLC and APs cant' be made trusted on ISE. ISE can trust only single root CA (2 years ago). So it could not auntheticate AP's certificates issued by 'additional' root CA on NAC port.&lt;/P&gt;&lt;P&gt;The task is done and we left the site, so it's final.&lt;/P&gt;&lt;P&gt;If only ISE could support several root CA's that time, then it could be possible to meke everything right.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 12:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4549529#M238265</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2022-02-10T12:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP AP 802.1x supplicant with EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4726190#M248614</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/538560"&gt;@Murinos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking at deploying EAP-TLS to a bunch of AireOS WAPs and I came across this thread. What do you mean by "ISE can only trust single root CA" ?&lt;/P&gt;
&lt;P&gt;ISE can have many different Trusted CA certs installed, for the purpose of checking the CLIENT certificate.&lt;/P&gt;
&lt;P&gt;What you are alluding to, is the fact that ISE only supports one EAP System certificate. This is still a limitation. But it's not a problem for clients who don't check the Authenticating Server's (RADIUS server's) certificate. e.g. In Windows supplicants you can turn that validation off.&lt;/P&gt;
&lt;P&gt;Anyway. Back to Cisco WAPs and EAP-TLS.&amp;nbsp; Your ISE PSN's should have their EAP System cert issued by the corporate PKI. But as far as the clients is concerned, they can have their certs issued by multiple different CA - as long as ISE has those CA certs installed under Trusted Certs, and the usage is ticked for "Client authentication".&lt;/P&gt;
&lt;P&gt;Are you 100% sure that the Cisco WAP expects to always see the ISE EAP cert signed by the same cert that signed the WAP cert? That would be weird.&lt;/P&gt;
&lt;P&gt;I am still trying to figure out how to get PKI certs onto a Cisco AireOS WAP without using SCEP.&amp;nbsp; I just want to install the cert manually.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 23:46:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-ap-802-1x-supplicant-with-eap-tls/m-p/4726190#M248614</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-11-22T23:46:15Z</dc:date>
    </item>
  </channel>
</rss>

