<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP Machine Authentication fails in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272472#M19929</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Colin, Could you please send me a copy of your diagram to &lt;A href="mailto:charlespdillon@gmail.com"&gt;charlespdillon@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Nov 2009 03:11:03 GMT</pubDate>
    <dc:creator>Chuck Dillon</dc:creator>
    <dc:date>2009-11-04T03:11:03Z</dc:date>
    <item>
      <title>PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272456#M19913</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I am using PEAP with the following setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC 4404&lt;/P&gt;&lt;P&gt;ACS Solutions Engine 4.01 (self signed cert)&lt;/P&gt;&lt;P&gt;Windows AD database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PEAP user authentication works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is, I need to only allow machines which are in AD as such I have configued Machine authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However this is failing with the below log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host/wks1.lnd.uk  Authen failed    EAP-TLS or PEAP authentication failed during SSL handshake&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the ACS for PEAP machine auth in all required places and on the client. I have read lots of info saying I need to configure AD to allow Machine Authentications, and cert auto enrollment etc.., is this the case and if so whats the easiest way to do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 00:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272456#M19913</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2021-07-04T00:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272457#M19914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May have made some progress, as far as I can tell as long as the ACS cert is copied to the client and put in the Local Computer store. That I believe should be enough.&lt;/P&gt;&lt;P&gt;I think when I installed the ACS cert on the client I went with the default which is NOT the Local Computer store.&lt;/P&gt;&lt;P&gt;(This is not the same as installing an idependant cert on the client, but rather just the Local machine, trusting the ACS)&lt;/P&gt;&lt;P&gt;Thats my thoughts anyway, I'll give it a try tomorrow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jul 2009 19:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272457#M19914</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-07-21T19:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272458#M19915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK&lt;/P&gt;&lt;P&gt;Logged into the laptop as a local admin and imported the ACS self signed cert in to: Physical Store: Trusted Root Cert Auths&amp;gt;Local Computer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This had the effect that my Machine Auth now no longer fails with the SSL error but now fails with "External DB user invalid or bad password"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unknown user policy is working as Domain user authentication is still working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone got any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2009 08:21:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272458#M19915</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-07-22T08:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272459#M19916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What username do you see in that "External DB User invalid" error in Failed Attempts log? Maybe it's "CN=&lt;USER&gt;"? &lt;/USER&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2009 12:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272459#M19916</guid>
      <dc:creator>Roman Rodichev</dc:creator>
      <dc:date>2009-07-22T12:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272460#M19917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;username in failure log is host/FQDM&lt;/P&gt;&lt;P&gt;ie host/laptop.x.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 10:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272460#M19917</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-07-28T10:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272461#M19918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi colin, &lt;/P&gt;&lt;P&gt;will u able to solve the problem if yes then can you share the solution among us&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2009 09:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272461#M19918</guid>
      <dc:creator>pandapritam</dc:creator>
      <dc:date>2009-08-04T09:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272462#M19919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yes &lt;/P&gt;&lt;P&gt;Did solve the problem, in my case I just loaded the Agent on another server and all Machine Auth is now working perfectly and all login scripts etc run ok. So it must have been an issue between the Agent and the server which happened to be a DC. Another company had tried getting this working before and failed so I suspect they messed around with the Agent privilages on the DC.&lt;/P&gt;&lt;P&gt;I have drawn up a diagram showing all PEAP components end to end and what needs to be configured and how. If you want a copy let me know ur E-mail address.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2009 09:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272462#M19919</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-08-04T09:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272463#M19920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks 4 the reply. i desperately need ur help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MY Emailid :&lt;A href="mailto:pritam.panda1@wipro.com"&gt;pritam.panda1@wipro.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2009 03:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272463#M19920</guid>
      <dc:creator>pandapritam</dc:creator>
      <dc:date>2009-08-05T03:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272464#M19921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm experience quite same problem with machine authen failed with host/ in another Domain Forest. Anyway could you also send me your diagram and how to setup agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:nuttea@mfec.co.th"&gt;nuttea@mfec.co.th&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2009 04:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272464#M19921</guid>
      <dc:creator>Nuttea Jirattivongvibul</dc:creator>
      <dc:date>2009-08-05T04:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272465#M19922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please send me @&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:k.patel@tatacommunications.com"&gt;k.patel@tatacommunications.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 18:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272465#M19922</guid>
      <dc:creator>kamlesh.patel</dc:creator>
      <dc:date>2009-08-21T18:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272466#M19923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please send me a copy @:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:jimhuangca@yahoo.ca"&gt;jimhuangca@yahoo.ca&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Aug 2009 04:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272466#M19923</guid>
      <dc:creator>jimcantire</dc:creator>
      <dc:date>2009-08-31T04:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272467#M19924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm in the process of deploying the same setup. Would I be  able to get a copy of your diagram @&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:mrspiro@gmail.com"&gt;mrspiro@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Sep 2009 21:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272467#M19924</guid>
      <dc:creator>spirotsares</dc:creator>
      <dc:date>2009-09-15T21:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272468#M19925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm in the process of implementing the same site, and I have presented a problem similar to yours I be able to obtain a copy of your diagram &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:pgonzalez@coasin.cl"&gt;pgonzalez@coasin.cl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Sep 2009 23:04:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272468#M19925</guid>
      <dc:creator>patgeo1984</dc:creator>
      <dc:date>2009-09-29T23:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272469#M19926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please send me a copy of that diagram to &lt;A href="mailto:ernandcorb@msn.com"&gt;ernandcorb@msn.com&lt;/A&gt;.  Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 12:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272469#M19926</guid>
      <dc:creator>edunn</dc:creator>
      <dc:date>2009-10-21T12:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272470#M19927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also trying to implement the same solution, would I be able to get a copy as &lt;A href="mailto:well....farhan.mirza@gtsi.com"&gt;well....farhan.mirza@gtsi.com&lt;/A&gt;..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 13:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272470#M19927</guid>
      <dc:creator>fmirza007</dc:creator>
      <dc:date>2009-10-23T13:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272471#M19928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;removed - wrong thread...sorry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Oct 2009 17:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272471#M19928</guid>
      <dc:creator>Robert.N.Barrett_2</dc:creator>
      <dc:date>2009-10-24T17:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272472#M19929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Colin, Could you please send me a copy of your diagram to &lt;A href="mailto:charlespdillon@gmail.com"&gt;charlespdillon@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 03:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272472#M19929</guid>
      <dc:creator>Chuck Dillon</dc:creator>
      <dc:date>2009-11-04T03:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272473#M19930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Colin, Could you also send me the solution? thanks a lot.&lt;/P&gt;&lt;P&gt;my email is &lt;A href="mailto:jason.majie@gmail.com"&gt;jason.majie@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Nov 2009 02:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272473#M19930</guid>
      <dc:creator>jason_majie</dc:creator>
      <dc:date>2009-11-10T02:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP Machine Authentication fails</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272474#M19931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're still checking this board, I would appreciate a copy of this diagram as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:ybaglakolov@gmail.com"&gt;ybaglakolov@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 21:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-fails/m-p/1272474#M19931</guid>
      <dc:creator>rmengert1</dc:creator>
      <dc:date>2009-12-03T21:33:17Z</dc:date>
    </item>
  </channel>
</rss>

