<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP : Machine authentication doesn't work in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316989#M20630</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Got machine auth working, by using a policy to specify the certificate to the workstations.&lt;/P&gt;&lt;P&gt;Although the mmc snap-in can also be used.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Mar 2005 18:19:39 GMT</pubDate>
    <dc:creator>colin.lynch</dc:creator>
    <dc:date>2005-03-22T18:19:39Z</dc:date>
    <item>
      <title>PEAP : Machine authentication doesn't work</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316986#M20627</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to set up machine authentication and at this time I have some problems.&lt;/P&gt;&lt;P&gt;I have the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- the users laptop are running WinXP&lt;/P&gt;&lt;P&gt;- the AP is a 1232&lt;/P&gt;&lt;P&gt;- ACS 3.3.2&lt;/P&gt;&lt;P&gt;- external database (Win2000 Active Directory) authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set up PEAP and it works well when a user is authenticated. However when I enable machine authentication on the ACS and also on the user laptop, it doesn't work. In the ACS logs I can see that the user has not authenticated due to the machine access restriction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Active Directory I changed the Dial In config. for the computers to allow access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else that has to be modified in order to perform machine authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone will be able to help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 17:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316986#M20627</guid>
      <dc:creator>alex.alexander</dc:creator>
      <dc:date>2021-07-04T17:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP : Machine authentication doesn't work</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316987#M20628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try after disabling peap session resume if it's enabled. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Mar 2005 16:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316987#M20628</guid>
      <dc:creator>bbaley</dc:creator>
      <dc:date>2005-03-18T16:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP : Machine authentication doesn't work</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316988#M20629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex&lt;/P&gt;&lt;P&gt;I have had a similar issue, I found that my PEAP users were fine but Machine authentication failed at the SSL handshake. I.E the machine didn't know where the local certificate was. In the meantime to get the policies working I unchecked the "validate server certificate" on the client. And that works, I would assume that the certificate needs to be in a specific default location for the machine authentication to use it, though thats just a guess.&lt;/P&gt;&lt;P&gt;I am spending the day to get this working and I'll post what I find out.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2005 09:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316988#M20629</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2005-03-22T09:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP : Machine authentication doesn't work</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316989#M20630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Got machine auth working, by using a policy to specify the certificate to the workstations.&lt;/P&gt;&lt;P&gt;Although the mmc snap-in can also be used.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2005 18:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316989#M20630</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2005-03-22T18:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP : Machine authentication doesn't work</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316990#M20631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this is a dumb response, but i got mine working after a bit of trouble....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;seems just like users you need to map the computer group to a group in ACS...(duh), so i mapped all the "domain computers" ad group into my dot1x group and got the machine authentication working (this was for my 802.1x wired project). It should work for wired and wireless though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 May 2005 02:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316990#M20631</guid>
      <dc:creator>mhernandez11</dc:creator>
      <dc:date>2005-05-25T02:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP : Machine authentication doesn't work</title>
      <link>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316991#M20632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I had the same problem. I solved it like this:&lt;/P&gt;&lt;P&gt;- In ACS go to Windows User Database Configuration&lt;/P&gt;&lt;P&gt;- "EAP-TLS and PEAP machine authentication name prefix" option, remove "/host" (i.e leave field empty).&lt;/P&gt;&lt;P&gt;- Check "Enable machine access restrictions"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this worked for me.&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Eniz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2005 13:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-machine-authentication-doesn-t-work/m-p/316991#M20632</guid>
      <dc:creator>eerten</dc:creator>
      <dc:date>2005-06-15T13:25:16Z</dc:date>
    </item>
  </channel>
</rss>

