<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wireless with PEAP Authentication not working using new NPS serv in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953887#M19385</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Scott that the issue is most likely your server certificate.&lt;/P&gt;&lt;P&gt;I have seen error messages like that a couple of times, and usually requesting a new computer certificate for the IAS/NPS (and changing the PEAP config to use it) did it for me.&lt;/P&gt;&lt;P&gt;Maybe you have the chance to get a server certificate from another NPS, where you know that it's working - for testing purposes?&lt;/P&gt;&lt;P&gt;I also would double-check Microsoft's requirements for NPS server certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Jun 2012 19:28:33 GMT</pubDate>
    <dc:creator>stefan.angerer</dc:creator>
    <dc:date>2012-06-29T19:28:33Z</dc:date>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS server</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953880#M19378</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are planning to migrate from our old IAS server to new NPS server. We are testing the new NPS server with our wireless infrastructure using WISM. We are using PEAP with server Cert for authentication. For testing purpose we are doing user authentication but our goal is to do machine authentication. On client side we are using Windows XP, Windows 7 &amp;amp; iPAD’s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe I have configured the NPS &amp;amp; CA server as per the documents I found on Cisco support forum &amp;amp; Microsoft’s site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it is not working for me. I am getting the following error message on the NPS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error # 1&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;Cryptographic operation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subject:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYSTEM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Account Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MADXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Account Domain:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logon ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x3e7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cryptographic Parameters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Provider Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft Software Key Storage Provider&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Algorithm Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RSA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XXX-Wireless-NPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key Type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Machine key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cryptographic Operation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Operation:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Return Code:&amp;nbsp; 0x80090010&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error # 2 &lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An error occurred during the Network Policy Server use of the Extensible Authentication Protocol (EAP). Check EAP log files for EAP errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if anyone has any insight on what is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Ds&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953880#M19378</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2021-07-04T05:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953881#M19379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your IAS configured for wireless already or are you doing a brand new install for wireless using NPS?  Do you guys have a CA that your issuing certificates or a third party?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post some screen shots of your NPS configuration or can you do an export and post that so we can see if your setting up NPS correctly?  Also or machine authentication, Windows 7 works fine, Windows XP requires a registry fix and how would you add the iPad to the computer OU? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 22:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953881#M19379</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-06-28T22:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953882#M19380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our Wireless with IAS server is working fine (with PEAP &amp;amp; Server Certs). We are doing a brand new install for wireless using NPS. We have also configured the NPS server as a CA server and the CA server has issued a Cert to NPS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should have stated this earlier that our CA server is a standalone server and not an Enterprise server. Our domain admins don't like them to integrate this server with AD. Therefore we push the root CA Cert to client using some other technique. Currently I am manually copying the cert on the workstation I am testing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached document for NPS configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently for testing purpose we are doing user authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 22:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953882#M19380</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-06-28T22:41:40Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953883#M19381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under the Network Policies &amp;gt; Constraints, I would only select the top two checkboxes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your client, I would not validate the server certificate for testing purposes. On your Windows 7, just select User for now.&amp;nbsp; If the authentication fails, can you post the log from the event viewer. What error do you see in the WLC.&amp;nbsp; YOu can run a debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug dot1x aaa&lt;/P&gt;&lt;P&gt;debug dot1x events&lt;/P&gt;&lt;P&gt;debug dot1x packets&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 23:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953883#M19381</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-06-28T23:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953884#M19382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have disabled MS-CHAP v1 &amp;amp; only MS-CHAP v2 is enabled on Network Policies &amp;gt; Constraints.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; disabled validate Certificate on Windows 7 and tried to authenticate, it is still failing. Here is the output from the event viewer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Cryptographic operation.&lt;/P&gt;&lt;P&gt;Subject:&lt;/P&gt;&lt;P&gt;Security ID: SYSTEM&lt;/P&gt;&lt;P&gt;Account Name: MADHFSVNPSPI01$&lt;/P&gt;&lt;P&gt;Account Domain: AD&lt;/P&gt;&lt;P&gt;Logon ID: 0x3e7&lt;/P&gt;&lt;P&gt;Cryptographic Parameters:&lt;/P&gt;&lt;P&gt;Provider Name: Microsoft Software Key Storage Provider&lt;/P&gt;&lt;P&gt;Algorithm Name: RSA&lt;/P&gt;&lt;P&gt;Key Name: DOT-Wireless-NPS&lt;/P&gt;&lt;P&gt;Key Type: Machine key.&lt;/P&gt;&lt;P&gt;Cryptographic Operation:&lt;/P&gt;&lt;P&gt;Operation: Decrypt.&lt;/P&gt;&lt;P&gt;Return Code: 0x80090010&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Network Policy Server denied access to a user.&lt;/P&gt;&lt;P&gt;Contact the Network Policy Server administrator for more information.&lt;/P&gt;&lt;P&gt;User:&lt;/P&gt;&lt;P&gt;Security ID: AD\mscdzs&lt;/P&gt;&lt;P&gt;Account Name: AD\mscdzs&lt;/P&gt;&lt;P&gt;Account Domain: AD&lt;/P&gt;&lt;P&gt;Fully Qualified Account Name: AD\mscdzs&lt;/P&gt;&lt;P&gt;Client Machine:&lt;/P&gt;&lt;P&gt;Security ID: NULL SID&lt;/P&gt;&lt;P&gt;Account Name: -&lt;/P&gt;&lt;P&gt;Fully Qualified Account Name: -&lt;/P&gt;&lt;P&gt;OS-Version: -&lt;/P&gt;&lt;P&gt;Called Station Identifier: 64-ae-0c-00-de-f0:DOT&lt;/P&gt;&lt;P&gt;Calling Station Identifier: a0-88-b4-e2-79-cc&lt;/P&gt;&lt;P&gt;NAS:&lt;/P&gt;&lt;P&gt;NAS IPv4 Address: 130.47.128.7&lt;/P&gt;&lt;P&gt;NAS IPv6 Address: -&lt;/P&gt;&lt;P&gt;NAS Identifier: WISM2B&lt;/P&gt;&lt;P&gt;NAS Port-Type: Wireless - IEEE 802.11&lt;/P&gt;&lt;P&gt;NAS Port: 29&lt;/P&gt;&lt;P&gt;RADIUS Client:&lt;/P&gt;&lt;P&gt;Client Friendly Name: WISM2B&lt;/P&gt;&lt;P&gt;Client IP Address: 130.47.128.7&lt;/P&gt;&lt;P&gt;Authentication Details:&lt;/P&gt;&lt;P&gt;Connection Request Policy Name: Secure Wireless Connections&lt;/P&gt;&lt;P&gt;Network Policy Name: Secure Wireless Connections&lt;/P&gt;&lt;P&gt;Authentication Provider: Windows&lt;/P&gt;&lt;P&gt;Authentication Server: MADHFSVNPSPI01.AD.DOT.STATE.WI.US&lt;/P&gt;&lt;P&gt;Authentication Type: PEAP&lt;/P&gt;&lt;P&gt;EAP Type: -&lt;/P&gt;&lt;P&gt;Account Session Identifier: -&lt;/P&gt;&lt;P&gt;Logging Results: Accounting information was written to the local log file.&lt;/P&gt;&lt;P&gt;Reason Code: 23&lt;/P&gt;&lt;P&gt;Reason: An error occurred during the Network Policy Server use of the Extensible Authentication Protocol (EAP). Check EAP log files for EAP errors.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Attached are EAP logs &amp;amp; debug logs from the controller. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the help. I really appreciate.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2012 14:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953884#M19382</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-06-29T14:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953885#M19383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It must be your certificate.&amp;nbsp; If you open up the mmc snap-in for certificates and you look in the computer personal certificate folder, next to the certificate, do you see a key icon on the top left side of the certificate cert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2012 15:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953885#M19383</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-06-29T15:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953886#M19384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the CA server side I see the key. On the client side (Windows 7) I don't because the server will not share his private key. I believe the key you are talking about is the private key. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the screen shot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/2/9/93920-Cert.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2012 16:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953886#M19384</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-06-29T16:19:27Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953887#M19385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Scott that the issue is most likely your server certificate.&lt;/P&gt;&lt;P&gt;I have seen error messages like that a couple of times, and usually requesting a new computer certificate for the IAS/NPS (and changing the PEAP config to use it) did it for me.&lt;/P&gt;&lt;P&gt;Maybe you have the chance to get a server certificate from another NPS, where you know that it's working - for testing purposes?&lt;/P&gt;&lt;P&gt;I also would double-check Microsoft's requirements for NPS server certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2012 19:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953887#M19385</guid>
      <dc:creator>stefan.angerer</dc:creator>
      <dc:date>2012-06-29T19:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953888#M19386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are doing peap, you don't need a client side cert.  I still believe the serve side cert is the cause of your issue.  I believe you can export the cert from your IAS and import that on the NPS for testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2012 23:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953888#M19386</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-06-29T23:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953889#M19387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I agree with you guys (Scott &amp;amp; Stefan). I am quite sure that the problem is the Server Certificate. How can I rectify that? My problem is when the CA server issues the certificate to the NPS server. It is not appearing on the Network Policies &amp;gt; Constraints &amp;gt; Authentication method &amp;gt; Microsoft: Protected EAP (PEAP). When I click Edit I am seeing CA server’s certificate and NOT the certificate he issued to the NPS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I get the issued cert by the CA server in Network Policies &amp;gt; Constraints &amp;gt; Authentication method &amp;gt; Microsoft: Protected EAP (PEAP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where exactly it is stored in the NPS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other problem I am thinking is that my CA server is an Enterprise Standalone server. It is not integrated with AD. Will it make any difference? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 15:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953889#M19387</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-07-02T15:25:36Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953890#M19388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You were correct. The problem was the Certificate. I was able to convince our Windows Server admin to install the CA server as Enterprise CA &amp;amp; not as Standalone CA. Once the server was integrated with Active Directory and we requested the Cert as per procedure (used by Windows) and not using the Web method. The requested Cert had the private key which was missing earlier. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again Thanks a lot Scott&amp;nbsp; !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This the best forum. No need to open TAC case. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 00:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953890#M19388</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2012-07-09T00:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless with PEAP Authentication not working using new NPS</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953891#M19389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well glad you have it working now. Thanks also for using the rating system:)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 00:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953891#M19389</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-07-09T00:56:45Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953892#M19390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're here, you may check out the doc attachment to &lt;SPAN style="font-size: 10pt;"&gt;dharmendra2shah post. It helped me a lot to find what was misconfigured on my NPS. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 18:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953892#M19390</guid>
      <dc:creator>Steve Berglund</dc:creator>
      <dc:date>2013-09-10T18:31:22Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953893#M19391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have read this complete listing at searching for an answer that clients are connected/authenticated over autonomous AP´s with PEAP working fine but not with the WLC5508 with 7.4.121.0. We plan here the migration to the controller and have test it with an 2602i AP. But the client that would be ok on autonomous AP, goes not in RUN state on the WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is the same GPO profile and the same NPS as RADIUS Server. DHCP are OK and the Events on the NPS show that the authentication is OK. The Server Certificate would not be checked and the NPS config was checked with the infos from the postings here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see in the debug logs from the wlc the similar messages as in the above posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have we here also the Problem with the Server certificate, but why it goes on autonomus but not over wlc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Feb 2014 13:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953893#M19391</guid>
      <dc:creator>mvolk</dc:creator>
      <dc:date>2014-02-01T13:31:31Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953894#M19392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The server certificate should be fine since the radius server is working with autonomous.&amp;nbsp; I think its your policies that is the issue and what is being sent back to the WLC versus an autonomous AP.&amp;nbsp; The easiest way to fix this is to go into your NPS and right click on your NPS (globe with the key) and export the configuration.&amp;nbsp; Email or PM that to me and I can look at how you can tweak your policies.&amp;nbsp; Also give me an overview of what you want... for example.... I want user in this AD group to be able to access the wireless on this SSID from a wireless device, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Feb 2014 15:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953894#M19392</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-02-01T15:45:15Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953895#M19393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the answer of my question!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, at the moment I don't have any chance to become the export file from the NPS, but I have make a snapshot from the Event Log that shows me it seems all good!? But I don´t know. &lt;/P&gt;&lt;P&gt;What we plan is to migrate about 25 Autonomous 1242AG AP´s to CAPWAP. The 1242AG works fine with the RADIUS and PEAP.&lt;/P&gt;&lt;P&gt;In this test we have setup the new 5508 WLC an have one CAP2602i attached on the WLC. We use the same SSID enrolled over GPO. The RADIUS for the WLC is OK, first we had here an mistake with the Key, this problem was fixed.&lt;/P&gt;&lt;P&gt;The NPS Policy is the same for the Autonomus and WLC Clients.&lt;/P&gt;&lt;P&gt;Why now the Client over the Autonomous AP is OK authenticated but not over the WLC. Where is the problem?&lt;/P&gt;&lt;P&gt;I have invite my colleagues to check the NPS config and policy again an check also the server certificate. I wait of his answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bye an thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/4/3/180341-NPS-Event.jpg" alt="NPS-Event.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 15:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953895#M19393</guid>
      <dc:creator>mvolk</dc:creator>
      <dc:date>2014-02-10T15:16:23Z</dc:date>
    </item>
    <item>
      <title>Wireless with PEAP Authentication not working using new NPS serv</title>
      <link>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953896#M19394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please scroll through the event log and see if the authentication actually shows hitting the correct policies in NPS?&amp;nbsp; I see from your screen shot that the result is Full Access, but you need to also verify that it indeed can for the WLC AAA client and is hitting the correct policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;*****Help out other by using the rating system and marking answered questions as "Answered"*****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 16:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-with-peap-authentication-not-working-using-new-nps/m-p/1953896#M19394</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-02-10T16:51:30Z</dc:date>
    </item>
  </channel>
</rss>

