<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP authentication failed during SSL handshake  in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211382#M18850</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I believe so. &lt;/P&gt;&lt;P&gt;I retrieved the root cert from CA and installed on the client machine to trust CA and CA-signed entity. is that what you are asking? When i go IE&amp;gt;Tools&amp;gt;Internet Option&amp;gt;Contents&amp;gt;Certificate&amp;gt;Trusted Root Cert, I can see the CA that signed Server Cert for ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Aug 2004 20:00:16 GMT</pubDate>
    <dc:creator>uggie</dc:creator>
    <dc:date>2004-08-04T20:00:16Z</dc:date>
    <item>
      <title>PEAP authentication failed during SSL handshake</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211380#M18848</link>
      <description>&lt;P&gt;it's killing me... my client is pressuring me big time for not being able to fix this issue!!! i might have to leave Cisco world if i dont fix this!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok, i have the followings in my production; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AP1200 with 12.2(15)XR&lt;/P&gt;&lt;P&gt;ACS 3.3&lt;/P&gt;&lt;P&gt;MS CA server on the same box as ACS (win2000 sp3)&lt;/P&gt;&lt;P&gt;non-Cisco Card but CCXv2 (atheros supplicant)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEAP works perrrrfect. but once switched to PEAP profile, i get this message "PEAP authentication failed during SSL handshake". I guess this is something to do with a cert. but I've gone thru CA installing procedure 1000 times already. no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing i noticed before i got out of the office today, the ACS/CA box was on AA domain, and the user was BB domain. does it matter?? these domains may not trust each other or one-way trust... i don't have a clue right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One another thing, as i'm working on enterprise environment I wanted to accomplish to maintain a pretty good security level using PEAP with TKIP and some kinda key-management (wpa or cckm). and I noticed the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even with LEAP,&lt;/P&gt;&lt;P&gt;* encryption mode tkip &lt;/P&gt;&lt;P&gt;* authentication key-management cckm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with the two options on, the client isn't even associating to the AP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only combination that works is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* encryption mode tkip wep128&lt;/P&gt;&lt;P&gt;* authentication key-management cckm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* encryption mode tkip&lt;/P&gt;&lt;P&gt;* authentication key-management wpa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any clue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks in advance whoever share the life-saving knowledge!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211380#M18848</guid>
      <dc:creator>uggie</dc:creator>
      <dc:date>2021-07-04T16:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication failed during SSL handshake</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211381#M18849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your client system recognize the root certificate for your ACS's cert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2004 17:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211381#M18849</guid>
      <dc:creator>gamccall</dc:creator>
      <dc:date>2004-08-04T17:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication failed during SSL handshake</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211382#M18850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I believe so. &lt;/P&gt;&lt;P&gt;I retrieved the root cert from CA and installed on the client machine to trust CA and CA-signed entity. is that what you are asking? When i go IE&amp;gt;Tools&amp;gt;Internet Option&amp;gt;Contents&amp;gt;Certificate&amp;gt;Trusted Root Cert, I can see the CA that signed Server Cert for ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2004 20:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-failed-during-ssl-handshake/m-p/211382#M18850</guid>
      <dc:creator>uggie</dc:creator>
      <dc:date>2004-08-04T20:00:16Z</dc:date>
    </item>
  </channel>
</rss>

