<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EAP-FAST, ACS, CSSC, AD password changes in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857601#M11004</link>
    <description>&lt;P&gt;We have been using 802.1x machine and user authentication via MS built-in supplicant (PEAP, MSCHAP-v2) and MS IAS (radius) backend on a wired network for about a year.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently migrated our 802.1x platform to CSSC 4.2 and ACS 4.1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I soon discovered that when MS AD informs the user that their password requires changing (after 30 days due to GP), the user happily changes their password, and soon after, CSSC authentication fails. A reboot and subsequent Logon resolves the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems CSSC has cached the initial logon details and has not updated itself when the password change took place?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anybody else experienced this problem and discovered a solution?&lt;/P&gt;&lt;P&gt;       &lt;/P&gt;</description>
    <pubDate>Sat, 03 Jul 2021 21:52:55 GMT</pubDate>
    <dc:creator>toddsandery</dc:creator>
    <dc:date>2021-07-03T21:52:55Z</dc:date>
    <item>
      <title>EAP-FAST, ACS, CSSC, AD password changes</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857601#M11004</link>
      <description>&lt;P&gt;We have been using 802.1x machine and user authentication via MS built-in supplicant (PEAP, MSCHAP-v2) and MS IAS (radius) backend on a wired network for about a year.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently migrated our 802.1x platform to CSSC 4.2 and ACS 4.1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I soon discovered that when MS AD informs the user that their password requires changing (after 30 days due to GP), the user happily changes their password, and soon after, CSSC authentication fails. A reboot and subsequent Logon resolves the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems CSSC has cached the initial logon details and has not updated itself when the password change took place?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anybody else experienced this problem and discovered a solution?&lt;/P&gt;&lt;P&gt;       &lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 21:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857601#M11004</guid>
      <dc:creator>toddsandery</dc:creator>
      <dc:date>2021-07-03T21:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST, ACS, CSSC, AD password changes</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857602#M11005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this happen everytime you logon with new password?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2007 22:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857602#M11005</guid>
      <dc:creator />
      <dc:date>2007-11-07T22:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST, ACS, CSSC, AD password changes</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857603#M11006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, whenever a password change is required by AD (once every 30 days). ACS then reports "Invalid Protocol Data" when the next 802.1x reauthentication occurs soon after the AD password change. The remote agent log shows the authentication as successful. Rebooting the PC resolves the issue for another 30 days but this is not acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using ACS 4.1.1.23.p5 CSSC 4.2.0.6187 and CTA 2.1.3.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2007 23:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-acs-cssc-ad-password-changes/m-p/857603#M11006</guid>
      <dc:creator>toddsandery</dc:creator>
      <dc:date>2007-11-07T23:11:10Z</dc:date>
    </item>
  </channel>
</rss>

