<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate problem with EAP-TLS/PEAP authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399294#M11278</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an issue getting EAP-TLS/PEAP (EAP-GTC) authentication to work.  I am using a MS Server 2003, Standard Ed. server for my CA and a separate MS Server 2003, SE for my ACS server.  I have completed all configuration steps outlined by Cisco and MS, but the server-side certificate doesn't seem to be right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I go to the CA's web site from my ACS box, I select Request Certificate -&amp;gt; Advanced Certificate Request -&amp;gt; Create and submit a request to this CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Certificate Template, I select Web Server.  Once I do this, the 'Mark keys as exportable' option box is greyed out, which prevents me assigning the private key to the certificate.  If I continue, generate, and install the certificate as is, the statement 'You have a private key that corresponds to this certificate' does not appear in the General section of the certificate properties.  The client-side certificate installs with all prerequisites met, including the above statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to authenticate with the client and receive the familiar 'EAP-TLS or PEAP authentication failed during SSL handshake' error, which tells me I still have a certificate problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate any assistance with this matter.&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 17:38:49 GMT</pubDate>
    <dc:creator>depwanguy</dc:creator>
    <dc:date>2021-07-04T17:38:49Z</dc:date>
    <item>
      <title>Certificate problem with EAP-TLS/PEAP authentication</title>
      <link>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399294#M11278</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an issue getting EAP-TLS/PEAP (EAP-GTC) authentication to work.  I am using a MS Server 2003, Standard Ed. server for my CA and a separate MS Server 2003, SE for my ACS server.  I have completed all configuration steps outlined by Cisco and MS, but the server-side certificate doesn't seem to be right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I go to the CA's web site from my ACS box, I select Request Certificate -&amp;gt; Advanced Certificate Request -&amp;gt; Create and submit a request to this CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Certificate Template, I select Web Server.  Once I do this, the 'Mark keys as exportable' option box is greyed out, which prevents me assigning the private key to the certificate.  If I continue, generate, and install the certificate as is, the statement 'You have a private key that corresponds to this certificate' does not appear in the General section of the certificate properties.  The client-side certificate installs with all prerequisites met, including the above statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to authenticate with the client and receive the familiar 'EAP-TLS or PEAP authentication failed during SSL handshake' error, which tells me I still have a certificate problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate any assistance with this matter.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 17:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399294#M11278</guid>
      <dc:creator>depwanguy</dc:creator>
      <dc:date>2021-07-04T17:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate problem with EAP-TLS/PEAP authentication</title>
      <link>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399295#M11279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Microsoft has changed the Web Server template with the release of the Windows 2003 Enterprise CA so that keys are no longer exportable and the option will be greyed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will have to create a new template that does so. Here are the steps:&lt;/P&gt;&lt;P&gt;1. Start &amp;gt; Run &amp;gt; certmpl.msc&lt;/P&gt;&lt;P&gt;2. Right-click Web Server template and choose Duplicate Template&lt;/P&gt;&lt;P&gt;3. Name the template something easy to identify like ACS.&lt;/P&gt;&lt;P&gt;4. Go to the Request Handling tab and check Allow private key to be exported.&lt;/P&gt;&lt;P&gt;5. Click on the CSPs button and check Microsoft Base Cryptographic Provider v1.0 and&lt;/P&gt;&lt;P&gt;click OK.&lt;/P&gt;&lt;P&gt;6. All other options can be left at default.&lt;/P&gt;&lt;P&gt;7. Click Apply and OK.&lt;/P&gt;&lt;P&gt;8. Open the CA MMC snap-in.&lt;/P&gt;&lt;P&gt;9. Right-click Certificate Templates and choose New &amp;gt; Certificate Template to Issue.&lt;/P&gt;&lt;P&gt;10. Choose the new template you created and click OK.&lt;/P&gt;&lt;P&gt;11. Restart the CA.&lt;/P&gt;&lt;P&gt;The new template will be included in the Certificate Template dropdown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2005 17:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399295#M11279</guid>
      <dc:creator>mchin345</dc:creator>
      <dc:date>2005-04-11T17:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate problem with EAP-TLS/PEAP authentication</title>
      <link>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399296#M11280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much for the info.  I made the modifications, but now I get an error which I have attached.  Is there something else I need to do?  Again, thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2005 12:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399296#M11280</guid>
      <dc:creator>depwanguy</dc:creator>
      <dc:date>2005-04-12T12:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate problem with EAP-TLS/PEAP authentication</title>
      <link>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399297#M11281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using Win2K as your AD Domain controller?  If so the setup you have will not work.  You'll have to load the CA server on a Win2K Server to make it work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2005 15:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-problem-with-eap-tls-peap-authentication/m-p/399297#M11281</guid>
      <dc:creator>coxendine</dc:creator>
      <dc:date>2005-06-14T15:45:31Z</dc:date>
    </item>
  </channel>
</rss>

