<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP authentication to LDAP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055446#M18642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nope, PEAP does not require the client to validate the server side certificate.  Only TLS requires mutual certificate validations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Feb 2009 20:46:03 GMT</pubDate>
    <dc:creator>Stephen Rodriguez</dc:creator>
    <dc:date>2009-02-20T20:46:03Z</dc:date>
    <item>
      <title>PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055439#M18635</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a working WLAN solution that uses PEAP (1252 AP's, WCS, 4400 controllers etc.). At the moment we authenticate against Active Directory via a Cisco ACS appliance (v4.1) - this works fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying to also get authentication working to our LDAP Server - however, ACS keeps reporting "Authentication type not supported by external DB".  It also doesn't seem to even try to contact the LDAP server looking at our LAN sniffer logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas ? Thanks, Tim.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 23:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055439#M18635</guid>
      <dc:creator>tjenkin2</dc:creator>
      <dc:date>2021-07-03T23:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055440#M18636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can't authenticate PEAP against LDAP (at least a non-Active Directory LDAP; I've never tried pointing to an Active Directory LDAP). PEAP is a Microsoft-funded "standard". If you still want to use EAP but don't want to deal with client certs (as in EAP-TLS), you can do EAP-GTC or EAP-FAST. The problem for lots of people with that is that Windows XP and Vista do not support it natively via ZeroConfig. You have to use a client such as Intel ProSet, Juniper Oddysey, or Cisco Secure Services Client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See &lt;A class="jive-link-custom" href="http://en.wikipedia.org/wiki/EAP-TLS#PEAPv1.2FEAP-GTC" target="_blank"&gt;http://en.wikipedia.org/wiki/EAP-TLS#PEAPv1.2FEAP-GTC&lt;/A&gt; for more info about EAP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2008 16:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055440#M18636</guid>
      <dc:creator>m.glosson</dc:creator>
      <dc:date>2008-08-14T16:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055441#M18637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using Novell LDAP with EAP-GTC and I believe that error message is due to certificates not being installed on the Novell side and on the Cisco ACS. I also seem to remember the ACS needing an admin account on the LDAP database to access it fully, unless you use specialized groups which you can map. There was also a cert.db7 file that you have to extract and add to the Cisco ACS as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2009 14:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055441#M18637</guid>
      <dc:creator>daniel.keith</dc:creator>
      <dc:date>2009-01-28T14:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055442#M18638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are trying to make an LDAP call to the Microsoft AD, it won't work.  The WLC only supports unencrypted LDAP calls, and AD only supports an ecrypted call.  in other words, the WLC only can do clear text passwords, and AD will not send them as clear text.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2009 15:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055442#M18638</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2009-01-28T15:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055443#M18639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am setting up a WLAN using WLAN 4404, ACS and 1130 AP's.  My customer is using a Novell network.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was going to setup the ACS and client to do PEAP and have the ACS authenticate via LDAP to the Novell server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will work won't it?  The customer does have a cert from Verisign that I will install on the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 20:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055443#M18639</guid>
      <dc:creator>srosenthal</dc:creator>
      <dc:date>2009-02-20T20:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055444#M18640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that should work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;although why you would buy a certificate to do PEAP, instead of using your own CA, or have the ACS generate it's own PEAP ceritificate.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 20:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055444#M18640</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2009-02-20T20:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055445#M18641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer already has several Verisign certs for their servers so I was just going to install one on the ACS also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried in the lab to have the ACS server self generate a cert and then connect via the wireless.  I added a user account on the ACS.  I can fully connect it I tell the laptop to not validate the server.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am missing something?  I thought I had to leave the box checked to validate the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 20:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055445#M18641</guid>
      <dc:creator>srosenthal</dc:creator>
      <dc:date>2009-02-20T20:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055446#M18642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nope, PEAP does not require the client to validate the server side certificate.  Only TLS requires mutual certificate validations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 20:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055446#M18642</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2009-02-20T20:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055447#M18643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PEAP with ACS-LDAP is supported with PEAP (EAP-GTC) and not with PEAP (EAP-MSCHAPV2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change you peap type from PEAP-mschapV2 to PEAP -EAP-GTC &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Table 1-3 EAP Authentication Protocol and User Database Compatibility  &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/o.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/o.html&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2009 21:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055447#M18643</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2009-03-06T21:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication to LDAP</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055448#M18644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doen't EAP-GTC require some sort of generic token card?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Mar 2009 23:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-to-ldap/m-p/1055448#M18644</guid>
      <dc:creator>srosenthal</dc:creator>
      <dc:date>2009-03-08T23:42:10Z</dc:date>
    </item>
  </channel>
</rss>

