<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client authentication issue with large certificates in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309395#M284773</link>
    <description>&lt;P&gt;what is radius you use is it ISE ?&lt;BR /&gt;MHM&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jul 2025 06:44:19 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-07-15T06:44:19Z</dc:date>
    <item>
      <title>Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309324#M284767</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;We have a strange issue. We use 9800-40 WLCs in HA-SSO deployment model. There is an WLAN network, clients authenticated by an external RADIUS server using certificates. If administrators use small certificate chains, authentication works perfectly. If they use longer chain, packets needs to be fragmented and authentication not works, packets don't arrive to the RADIUS server.&lt;/P&gt;
&lt;P&gt;We did some packet capture on the client and saw that if they use the small certificate chain the fragments flag was set to 0. If they use the big certificate chain the fragments flag was set to 1 and the packet didn't reach RADIUS server.&lt;/P&gt;
&lt;P&gt;What can be the problem, what should we check? Is that issue can be related to WLC configuration? Maybe related to capwap or MTU configuration?&lt;/P&gt;
&lt;P&gt;Using small cert, auth works:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schulcz_3-1752536242081.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248270iB617826226C30D8B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="schulcz_3-1752536242081.png" alt="schulcz_3-1752536242081.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Using large cert, auth not works, packet don't arrive to RADIUS server:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schulcz_2-1752536188179.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248269i94FE82B6B4093172/image-size/medium?v=v2&amp;amp;px=400" role="button" title="schulcz_2-1752536188179.png" alt="schulcz_2-1752536188179.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 23:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309324#M284767</guid>
      <dc:creator>schulcz</dc:creator>
      <dc:date>2025-07-14T23:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309382#M284769</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/84336"&gt;@schulcz&lt;/a&gt;&amp;nbsp; &amp;nbsp; Review this document :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/222920-understand-radius-mtu-and-fragmentation.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/222920-understand-radius-mtu-and-fragmentation.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 06:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309382#M284769</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-07-15T06:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309395#M284773</link>
      <description>&lt;P&gt;what is radius you use is it ISE ?&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 06:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309395#M284773</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-15T06:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309559#M284786</link>
      <description>&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;shared, you can have a look into&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo58100" target="_self"&gt;CSCwo58100&lt;/A&gt;&amp;nbsp;as well.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 13:17:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309559#M284786</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-07-15T13:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309609#M284796</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/853834"&gt;@Saikat Nandy&lt;/a&gt;&amp;nbsp;- Thank you for sharing that bug. It says it's fixed, but no releases are specified. Can you share information about which version(s) it's fixed in? Also does it affect all 17.12.x versions/service packs at least up to 17.12.4 APSP8, and will it affect local mode as well or specifically flex/central auth?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 14:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309609#M284796</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2025-07-15T14:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309668#M284800</link>
      <description>&lt;P&gt;Yeah pretty much all the 17.12.x are affected. 17.12.6 where the fix has been added. APSP on top of 17.12.5 is in progress.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 17:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309668#M284800</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-07-15T17:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309728#M284803</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/853834"&gt;@Saikat Nandy&lt;/a&gt;&amp;nbsp;Thank you! I forgot to ask, does it&amp;nbsp;&lt;EM&gt;only&lt;/EM&gt; occur in FlexConnect mode with central auth, or will local mode be affected also?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 20:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5309728#M284803</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2025-07-15T20:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5310204#M284827</link>
      <description>&lt;P&gt;Yes..apparently that's what have been observed so far - Flex: central auth+local switching.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 17:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5310204#M284827</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-07-16T17:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Client authentication issue with large certificates</title>
      <link>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5310305#M284840</link>
      <description>&lt;P&gt;I would to share this doc from Cisco&amp;nbsp; explain some workaround to deal with fragment of radius frame&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/222920-understand-radius-mtu-and-fragmentation.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/222920-understand-radius-mtu-and-fragmentation.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;One workaround which I see solution for his issue is using specific source interface to connect to server instead of wmi which is defualt select by wlc.&lt;/P&gt;
&lt;P&gt;This interface have mtu 1500 where wmi have less mtu than 1500 and this lead to fragment and drop of frame&lt;/P&gt;
&lt;P&gt;Thanks for all&lt;/P&gt;
&lt;P&gt;Have a nice day&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 21:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-authentication-issue-with-large-certificates/m-p/5310305#M284840</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-16T21:59:55Z</dc:date>
    </item>
  </channel>
</rss>

