<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobility Express Local EAP Certificate in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478218#M233944</link>
    <description>&lt;P&gt;Thank you very much, very helpful information. But still not working.&lt;/P&gt;&lt;P&gt;With a Windows client, it doesn't show me a server certificate to accept and it doesn't connect&lt;/P&gt;&lt;P&gt;With an android client, it only connects if I choose not validate server certificate.&lt;/P&gt;&lt;P&gt;It seems there is a problem with the certificate or the ca certificate.&lt;/P&gt;&lt;P&gt;Which eap CA certificate do I have to upload to the controller? root CA or&amp;nbsp; Intermediate CA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Oct 2021 10:50:36 GMT</pubDate>
    <dc:creator>jmprats</dc:creator>
    <dc:date>2021-10-01T10:50:36Z</dc:date>
    <item>
      <title>Mobility Express Local EAP Certificate</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4471856#M233589</link>
      <description>&lt;P&gt;I want to use PEAP with ME with Local Authentication. It works but it shows to the users the internal certificate issued by Cisco Manufacturing CA. I have got in the controller a public certificate that I am using with the captive portal. How can I use my certificate with Local EAP?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 07:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4471856#M233589</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2021-09-23T07:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility Express Local EAP Certificate</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4471864#M233590</link>
      <description>&lt;P&gt;Follow this guide to install the device certificate either signed by company CA or you can also signed it it with public certificate authority (ex: global sign)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/100590-ldap-eapfast-config.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/100590-ldap-eapfast-config.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to arte helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 07:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4471864#M233590</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2021-09-23T07:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility Express Local EAP Certificate</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4471940#M233593</link>
      <description>&lt;P&gt;Thank you. I will try later in a maintenance window. I don't want to take any risk of side effects changing the controller certificate.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 10:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4471940#M233593</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2021-09-23T10:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility Express Local EAP Certificate</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478104#M233918</link>
      <description>&lt;P&gt;I finally installed the eap public certificate (third party certificate) with "&lt;STRONG&gt;transfer download datatype eapdevcert&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;command and rebooted the controller.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After the reboot, the command "show certificate eap" shows the new installed certificate but when I connect to the Wlan with PEAP with local users the AP shows me the Cisco preconfigured certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I use my third&amp;nbsp;party certificate?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do I have to select the certificate in the WLC configuration?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 06:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478104#M233918</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2021-10-01T06:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility Express Local EAP Certificate</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478175#M233934</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you already installed that you can use the vendor certificate instead of cisco, check this :&lt;/P&gt;
&lt;P&gt;---------------------------&lt;/P&gt;
&lt;P class="ph cmd"&gt;Configure certificate parameters per profile by entering these commands:&lt;/P&gt;
&lt;UL class="ul choices"&gt;
&lt;LI id="ID1923__choice_F3EB0A406412491B89B4E9A798F48D74" class="li choice"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config local-auth eap-profile method fast local-cert&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;enable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;disable&lt;/SPAN&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;profile_name&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;— Specifies whether the device certificate on the controller is required for authentication.
&lt;TABLE class="olh_note" role="note" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="1%" class="td_faq"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD class="td_faq"&gt;
&lt;SECTION class="note__content"&gt;
&lt;P class="p N3_Note3-EDF3A6FC"&gt;This command applies only to EAP-FAST because device certificates are not used with LEAP and are mandatory for EAP-TLS and PEAP.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/LI&gt;
&lt;LI id="ID1923__choice_CB1737DB7D63458BA8B24B5DF5B20D2E" class="li choice"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;config local-auth eap-profile method fast client-cert&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;enable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;disable&lt;/SPAN&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;profile_name&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;— Specifies whether wireless clients are required to send their device certificates to the controller in order to authenticate.
&lt;TABLE class="olh_note" role="note" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="1%" class="td_faq"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD class="td_faq"&gt;
&lt;SECTION class="note__content"&gt;
&lt;P class="p N3_Note3-EDF3A6FC"&gt;This command applies only to EAP-FAST because client certificates are not used with LEAP or PEAP and are mandatory for EAP-TLS.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/LI&gt;
&lt;LI id="ID1923__choice_736F62F379B343B08988AF7A7E744BA7" class="li choice"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config local-auth eap-profile cert-issuer&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;cisco&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;vendor&lt;/SPAN&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;profile_name&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;—If you specified EAP-FAST with certificates, EAP-TLS, or PEAP, specifies whether the certificates that will be sent to the client are from Cisco or another vendor.&lt;/LI&gt;
&lt;LI id="ID1923__choice_A3BF06949FF144C782A7DADF6B76B29F" class="li choice"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config local-auth eap-profile cert-verify ca-issuer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;enable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;disable&lt;/SPAN&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;profile_name&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;—If you chose EAP-FAST with certificates or EAP-TLS, specifies whether the incoming certificate from the client is to be validated against the CA certificates on the controller.&lt;/LI&gt;
&lt;LI id="ID1923__choice_69D8147330D54EC99263E9B46301A255" class="li choice"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config local-auth eap-profile cert-verify cn-verify&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;enable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;disable&lt;/SPAN&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;profile_name&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;—If you chose EAP-FAST with certificates or EAP-TLS, specifies whether the common name (CN) in the incoming certificate is to be validated against the CA certificates’ CN on the controller.&lt;/LI&gt;
&lt;LI id="ID1923__choice_5A5BB2206C054AC192EE6B75A923C333" class="li choice"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config local-auth eap-profile cert-verify date-valid&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;enable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd Keyword-ACC52ED6"&gt;disable&lt;/SPAN&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;profile_name&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;—If you chose EAP-FAST with certificates or EAP-TLS, specifies whether the controller is to verify that the incoming device certificate is still valid and has not expired.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;---------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 08:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478175#M233934</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2021-10-01T08:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility Express Local EAP Certificate</title>
      <link>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478218#M233944</link>
      <description>&lt;P&gt;Thank you very much, very helpful information. But still not working.&lt;/P&gt;&lt;P&gt;With a Windows client, it doesn't show me a server certificate to accept and it doesn't connect&lt;/P&gt;&lt;P&gt;With an android client, it only connects if I choose not validate server certificate.&lt;/P&gt;&lt;P&gt;It seems there is a problem with the certificate or the ca certificate.&lt;/P&gt;&lt;P&gt;Which eap CA certificate do I have to upload to the controller? root CA or&amp;nbsp; Intermediate CA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 10:50:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-express-local-eap-certificate/m-p/4478218#M233944</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2021-10-01T10:50:36Z</dc:date>
    </item>
  </channel>
</rss>

