<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Certificate will not be recognized in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540393#M219152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is how it works when you select the certificate method under the WZC:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Computer authentication works &lt;STRONG&gt;only &lt;/STRONG&gt;before logon &lt;/LI&gt;&lt;LI&gt;By default, after logon, only &lt;STRONG&gt;user&lt;/STRONG&gt; authentication works. This means that each user on the system needs a certificate (!) including administrator &lt;UL&gt;&lt;LI&gt;This can be overridden by AuthMode=2, but this is system-wide,&amp;nbsp; implying that for a different wireless network user authentication won't&amp;nbsp; work either. So AuthMode is not an option (except the computer is &lt;STRONG&gt;only&lt;/STRONG&gt; used in one 802.1X network) &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;This implies too that as soon as there is a computer certificate and no user certificate the network just does not work! &lt;/LI&gt;&lt;LI&gt;This way it is not possible to use e.g. EAP-TLS with&amp;nbsp; certificates for computers and PEAP-MSCHAPv2 with username/password for&amp;nbsp; users &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you wish to use certificate based authentication for the machine, you need to use also for user authentication (using WZC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have both user and machine certificate, then after installing the certs, reboot the machine and verify if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Dec 2010 21:35:33 GMT</pubDate>
    <dc:creator>Tiago Antunes</dc:creator>
    <dc:date>2010-12-10T21:35:33Z</dc:date>
    <item>
      <title>Machine Certificate will not be recognized</title>
      <link>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540392#M219151</link>
      <description>&lt;P&gt;Hi All, i have a Setup as Follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- 5508/1142&lt;/P&gt;&lt;P&gt;- heterogenous Client with WZC, XP, SP3, SSO&lt;/P&gt;&lt;P&gt;- ACS 5.2, MS AD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Target is Songle Sign On wih Machine Cerificates against AD. For testing purpose we tested with EAP-PEAP/MS Chapv2 and Machine Auth, works fine. Now we installed a Machine cert in the Machine cert Store (no User Cert) and reconfigured the WZC for using certs and Machin Auth. What we see is an Error Message in the System Tray that there is no certificate available. We checked it again, the MMC shows us a Machine cert in the Store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where am i wrong, any help welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR, Michael&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 02:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540392#M219151</guid>
      <dc:creator>MICHAEL SCHROEDER</dc:creator>
      <dc:date>2021-07-04T02:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate will not be recognized</title>
      <link>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540393#M219152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is how it works when you select the certificate method under the WZC:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Computer authentication works &lt;STRONG&gt;only &lt;/STRONG&gt;before logon &lt;/LI&gt;&lt;LI&gt;By default, after logon, only &lt;STRONG&gt;user&lt;/STRONG&gt; authentication works. This means that each user on the system needs a certificate (!) including administrator &lt;UL&gt;&lt;LI&gt;This can be overridden by AuthMode=2, but this is system-wide,&amp;nbsp; implying that for a different wireless network user authentication won't&amp;nbsp; work either. So AuthMode is not an option (except the computer is &lt;STRONG&gt;only&lt;/STRONG&gt; used in one 802.1X network) &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;This implies too that as soon as there is a computer certificate and no user certificate the network just does not work! &lt;/LI&gt;&lt;LI&gt;This way it is not possible to use e.g. EAP-TLS with&amp;nbsp; certificates for computers and PEAP-MSCHAPv2 with username/password for&amp;nbsp; users &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you wish to use certificate based authentication for the machine, you need to use also for user authentication (using WZC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have both user and machine certificate, then after installing the certs, reboot the machine and verify if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 21:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540393#M219152</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-10T21:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate will not be recognized</title>
      <link>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540394#M219153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great job on the explation T .. 5 stars&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put a few missing links together for me ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Dec 2010 04:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540394#M219153</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2010-12-12T04:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate will not be recognized</title>
      <link>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540395#M219154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tiago,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is exactly what i wanted to know, thanks a lot. I will discuss the Autoenrollment of User Certificates with my Customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again and 5 Stars on that!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Dec 2010 17:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540395#M219154</guid>
      <dc:creator>MICHAEL SCHROEDER</dc:creator>
      <dc:date>2010-12-12T17:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Certificate will not be recognized</title>
      <link>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540396#M219155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one additional Question; what exactly is checked if i dont use Certificates (Customer Decision) but only the Computer against AD, simply the Hostname or his SID? Can i influence that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx and Regards, Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jan 2011 13:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/machine-certificate-will-not-be-recognized/m-p/1540396#M219155</guid>
      <dc:creator>MICHAEL SCHROEDER</dc:creator>
      <dc:date>2011-01-24T13:07:22Z</dc:date>
    </item>
  </channel>
</rss>

