<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wireless Authentication with Certificate Only Failure in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486626#M296862</link>
    <description>&lt;P&gt;Take a look at the documentation.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Meraki_Local_Authentication_-_MR_802.1X" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Meraki_Local_Authentication_-_MR_802.1X&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I suggest that if the documentation doesn't help you open a support case.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 13:29:20 GMT</pubDate>
    <dc:creator>aleabrahao</dc:creator>
    <dc:date>2024-01-12T13:29:20Z</dc:date>
    <item>
      <title>Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486623#M296859</link>
      <description>&lt;P&gt;We are trying to setup wireless authentication using certificate alone and configured the SSID access control according to this article &lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Meraki_Local_Authentication_-_MR_802.1X" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Meraki_Local_Authentication_-_MR_802.1X&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is the resulting setting for us&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Danimax01_0-1705064756103.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/273173i8E3426837AAFF66B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We want to use only certificate to authenticate and use the in-built radius server in Meraki AP because we don't have any on-premise infrastructure at all.&lt;/P&gt;&lt;P&gt;Whenever laptop try to connect to the SSID, they get prompted for username and passowrd, even though the certificate has been deployed on the  laptop and the connection fails with error Failed authentication EAP Failure.&lt;/P&gt;&lt;P&gt;Why is it prompting user for username and password eventhough we enabled only certificate authentication and disabled password authentication.&lt;/P&gt;&lt;P&gt;Any help or suggestion will be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 13:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486623#M296859</guid>
      <dc:creator>danimax01</dc:creator>
      <dc:date>2024-01-12T13:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486624#M296860</link>
      <description>&lt;P&gt;Ensure that the certificate is correctly configured on the client devices. The certificate should be installed in the correct certificate store on the device.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 13:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486624#M296860</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2024-01-12T13:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486625#M296861</link>
      <description>&lt;P&gt;The certificate are installed on Personal store for both local computer and current user.&lt;/P&gt;&lt;P&gt;The Iden Trust root CA is installed on Trusted Root CA Store&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 13:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486625#M296861</guid>
      <dc:creator>danimax01</dc:creator>
      <dc:date>2024-01-12T13:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486626#M296862</link>
      <description>&lt;P&gt;Take a look at the documentation.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Meraki_Local_Authentication_-_MR_802.1X" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Meraki_Local_Authentication_-_MR_802.1X&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I suggest that if the documentation doesn't help you open a support case.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 13:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486626#M296862</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2024-01-12T13:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486627#M296863</link>
      <description>&lt;P&gt;I reference the doc already.&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Is the SSID still meant to prompt for username and password even though i enabled only certificate authentication?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 13:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486627#M296863</guid>
      <dc:creator>danimax01</dc:creator>
      <dc:date>2024-01-12T13:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486628#M296864</link>
      <description>&lt;P&gt;Theoretically it wasn't.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 13:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486628#M296864</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2024-01-12T13:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486629#M296865</link>
      <description>&lt;P&gt;Thank you for your contribution.&lt;/P&gt;&lt;P&gt;i will open a support case.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 14:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486629#M296865</guid>
      <dc:creator>danimax01</dc:creator>
      <dc:date>2024-01-12T14:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486630#M296866</link>
      <description>&lt;P&gt;It is normal to see a request for username and password if there is no WLAN profile configured on the client. The client doesn’t have any knowledge if the System wants username/password or a certificate. But when choosing EAP-TLS at least the password request should go away. At least this is how it works for me.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 21:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486630#M296866</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2024-01-12T21:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486631#M296867</link>
      <description>&lt;P&gt;^ This ^ .  Your client has to be configured to use EAP-TLS instead of EAP-PEAP and does have to know what cert to use for user auth.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2024 11:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486631#M296867</guid>
      <dc:creator>joey.debra</dc:creator>
      <dc:date>2024-01-14T11:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486632#M296868</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/15353"&gt;@joey.debra&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Can you tell me how you set up the profile?&lt;/P&gt;&lt;P&gt;I created an SSID and exported the root certificate from my client certificate and uploaded it as a PEM in the dashboard.&lt;/P&gt;&lt;P&gt;I set up the WLAN profile as described here at Cisco (only the section for the profile): &lt;A href="https://www.cisco.com/c/de_de/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html#toc-hId-408191516" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/de_de/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html#toc-hId-408191516&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However, a connection is still not possible.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The event log in the dashboard only shows "802.1X Failed authentication (EAP failure)".&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 10:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486632#M296868</guid>
      <dc:creator>SPCHO</dc:creator>
      <dc:date>2024-02-16T10:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless Authentication with Certificate Only Failure</title>
      <link>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486633#M296869</link>
      <description>&lt;P&gt;any luck? I'm having the same issues with the same setup&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 17:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-authentication-with-certificate-only-failure/m-p/5486633#M296869</guid>
      <dc:creator>carl.slater</dc:creator>
      <dc:date>2024-08-13T17:32:36Z</dc:date>
    </item>
  </channel>
</rss>

