<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wpa_supplicant running EAP-TLS on ubuntu in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999482#M108965</link>
    <description>&lt;P&gt;Hi all-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5520 controller running 8.5.140 and a 3702 AP in local mode.&amp;nbsp; I have other devices of various types concected to this SSID using EAP-TLS, so I am confident in the controller config (WPA2 Policy, WPA2 Encryption=AES, Authentication Key Management=802.1x)&lt;/P&gt;&lt;P&gt;I have a linux device that I am trying to connect via EAP-TLS.&amp;nbsp; The deice is using wpa_supplicant.&amp;nbsp; the config file is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;network={&lt;BR /&gt;ssid="mySSID"&lt;BR /&gt;proto=RSN&lt;BR /&gt;key_mgmt=IEEE8021X&lt;BR /&gt;eap=TLS&lt;BR /&gt;scan_ssid=1&lt;BR /&gt;identity="myDevice"&lt;BR /&gt;ca_cert="/etc/certs/cacert.pem"&lt;BR /&gt;client_cert="/etc/certs/myDev.cer"&lt;BR /&gt;private_key="/etc/certs/myDevkey"&lt;BR /&gt;eapol_flags=3&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The controller debug just shows the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*spamApTask3: Dec 16 09:53:46.861: b0:1f:81:d5:07:23 Association Failed on REAP AP BSSID ec:bd:1d:15:7b:d7 (slot 1), status 13 0 rsnie-osnie accept failed&lt;BR /&gt;*spamApTask1: Dec 16 09:53:52.260: b0:1f:81:d5:07:23 Association Failed on REAP AP BSSID 58:f3:9c:fb:a8:37 (slot 1), status 13 0 rsnie-osnie accept failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have a config that works for wpa_supplicant and EAP-TLS?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 18:26:16 GMT</pubDate>
    <dc:creator>Wes Schochet</dc:creator>
    <dc:date>2021-07-05T18:26:16Z</dc:date>
    <item>
      <title>wpa_supplicant running EAP-TLS on ubuntu</title>
      <link>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999482#M108965</link>
      <description>&lt;P&gt;Hi all-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5520 controller running 8.5.140 and a 3702 AP in local mode.&amp;nbsp; I have other devices of various types concected to this SSID using EAP-TLS, so I am confident in the controller config (WPA2 Policy, WPA2 Encryption=AES, Authentication Key Management=802.1x)&lt;/P&gt;&lt;P&gt;I have a linux device that I am trying to connect via EAP-TLS.&amp;nbsp; The deice is using wpa_supplicant.&amp;nbsp; the config file is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;network={&lt;BR /&gt;ssid="mySSID"&lt;BR /&gt;proto=RSN&lt;BR /&gt;key_mgmt=IEEE8021X&lt;BR /&gt;eap=TLS&lt;BR /&gt;scan_ssid=1&lt;BR /&gt;identity="myDevice"&lt;BR /&gt;ca_cert="/etc/certs/cacert.pem"&lt;BR /&gt;client_cert="/etc/certs/myDev.cer"&lt;BR /&gt;private_key="/etc/certs/myDevkey"&lt;BR /&gt;eapol_flags=3&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The controller debug just shows the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*spamApTask3: Dec 16 09:53:46.861: b0:1f:81:d5:07:23 Association Failed on REAP AP BSSID ec:bd:1d:15:7b:d7 (slot 1), status 13 0 rsnie-osnie accept failed&lt;BR /&gt;*spamApTask1: Dec 16 09:53:52.260: b0:1f:81:d5:07:23 Association Failed on REAP AP BSSID 58:f3:9c:fb:a8:37 (slot 1), status 13 0 rsnie-osnie accept failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have a config that works for wpa_supplicant and EAP-TLS?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 18:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999482#M108965</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2021-07-05T18:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: wpa_supplicant running EAP-TLS on ubuntu</title>
      <link>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999509#M108966</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- You may be hitting a CCKM &lt;FONT color="#0000FF"&gt;compliance&lt;/FONT&gt; issue ; check the following :&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless-and-mobility/ccx-devices-matrix-support/td-p/2726474" target="_blank"&gt;https://community.cisco.com/t5/wireless-and-mobility/ccx-devices-matrix-support/td-p/2726474&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I also found a related bug report :&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf55570/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf55570/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 17:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999509#M108966</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2019-12-16T17:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: wpa_supplicant running EAP-TLS on ubuntu</title>
      <link>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999543#M108967</link>
      <description>I guess I don't understand how CCKM interacts with 802.1x. In my mind they are totally separate. What is the interaction there?</description>
      <pubDate>Mon, 16 Dec 2019 18:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/3999543#M108967</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2019-12-16T18:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: wpa_supplicant running EAP-TLS on ubuntu</title>
      <link>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/4003299#M108968</link>
      <description>&lt;P&gt;The setting "&lt;SPAN&gt;key_mgmt=IEEE8021X" in your wpa_supplicant.conf file is for WEP keys only.&amp;nbsp; You mentioned you are using WPA2, so you should use the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;key_mgmt=WPA-EAP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, if you don't want to be prompted for the private key password, you can add the following line under private_key:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;private_key_passwd="password"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dennis Bland&lt;/P&gt;&lt;P&gt;dB Performance Inc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 03:16:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/4003299#M108968</guid>
      <dc:creator>Dennis Bland</dc:creator>
      <dc:date>2019-12-25T03:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: wpa_supplicant running EAP-TLS on ubuntu</title>
      <link>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/4005244#M108969</link>
      <description>Thanks! That did the trick!</description>
      <pubDate>Tue, 31 Dec 2019 21:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-supplicant-running-eap-tls-on-ubuntu/m-p/4005244#M108969</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2019-12-31T21:16:41Z</dc:date>
    </item>
  </channel>
</rss>

