<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC Local EAP &amp; LDAP authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-local-eap-ldap-authentication/m-p/2916568#M39558</link>
    <description>&lt;P&gt;I'm trying to get an SSID to authenticate users using local EAP with LDAP.&amp;nbsp; The customer doesn't want to use a RADIUS server.&amp;nbsp; I've got the LDAP server configured and when I do a debug aaa ldap enable I can see a successful bind, but the authentication fails.&amp;nbsp; I get the following error:&lt;/P&gt;
&lt;P&gt;*LDAP DB Task 1: May 12 14:44:50.714: ldapInitAndBind [1] called lcapi_init (rc = 0 - Success)&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.717: ldapInitAndBind [1] configured Method Authenticated lcapi_bind (rc = 0 - Success)&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.717: LDAP server 1 changed state to CONNECTED&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.717: disabled LDAP_OPT_REFERRALS&lt;/P&gt;
&lt;P&gt;*LDAP DB Task 1: May 12 14:44:50.717: LDAP_CLIENT: UID Search (base=OU=Departments,DC=mydomain,DC=com, pattern=(&amp;amp;(objectclass=Person)(sAMAccountName=user@mydomain.com)))&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: ldap_search_ext_s returns 0 -5&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Returned 1 msgs including 0 references&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Returned msg 1 type 0x65&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT : No matched DN&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT : Check result error 0 rc 1013&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Received no referrals in search result msg&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Received 1 attributes in search result msg&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: ldapAuthRequest [1] 172.16.4.30 - 389 called lcapi_query base="OU=Departments,DC=mydomain,DC=com" type="Person" attr="sAMAccountName" user="user@mydomain.com" (rc = 0 - Success)&lt;BR /&gt;&lt;STRONG&gt;*LDAP DB Task 1: May 12 14:44:50.718: Handling LDAP response Authentication Failed&lt;/STRONG&gt;&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: Authenticated bind : Closing the binded session&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We've verified the credentials and tried all of the options in the EAP profile?&amp;nbsp; Anyone have this working that can help out?&amp;nbsp; Is there something else specific I need to do on the client side?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 12:03:07 GMT</pubDate>
    <dc:creator>chevymannie</dc:creator>
    <dc:date>2021-07-05T12:03:07Z</dc:date>
    <item>
      <title>WLC Local EAP &amp; LDAP authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-local-eap-ldap-authentication/m-p/2916568#M39558</link>
      <description>&lt;P&gt;I'm trying to get an SSID to authenticate users using local EAP with LDAP.&amp;nbsp; The customer doesn't want to use a RADIUS server.&amp;nbsp; I've got the LDAP server configured and when I do a debug aaa ldap enable I can see a successful bind, but the authentication fails.&amp;nbsp; I get the following error:&lt;/P&gt;
&lt;P&gt;*LDAP DB Task 1: May 12 14:44:50.714: ldapInitAndBind [1] called lcapi_init (rc = 0 - Success)&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.717: ldapInitAndBind [1] configured Method Authenticated lcapi_bind (rc = 0 - Success)&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.717: LDAP server 1 changed state to CONNECTED&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.717: disabled LDAP_OPT_REFERRALS&lt;/P&gt;
&lt;P&gt;*LDAP DB Task 1: May 12 14:44:50.717: LDAP_CLIENT: UID Search (base=OU=Departments,DC=mydomain,DC=com, pattern=(&amp;amp;(objectclass=Person)(sAMAccountName=user@mydomain.com)))&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: ldap_search_ext_s returns 0 -5&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Returned 1 msgs including 0 references&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Returned msg 1 type 0x65&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT : No matched DN&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT : Check result error 0 rc 1013&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Received no referrals in search result msg&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: LDAP_CLIENT: Received 1 attributes in search result msg&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: ldapAuthRequest [1] 172.16.4.30 - 389 called lcapi_query base="OU=Departments,DC=mydomain,DC=com" type="Person" attr="sAMAccountName" user="user@mydomain.com" (rc = 0 - Success)&lt;BR /&gt;&lt;STRONG&gt;*LDAP DB Task 1: May 12 14:44:50.718: Handling LDAP response Authentication Failed&lt;/STRONG&gt;&lt;BR /&gt;*LDAP DB Task 1: May 12 14:44:50.718: Authenticated bind : Closing the binded session&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We've verified the credentials and tried all of the options in the EAP profile?&amp;nbsp; Anyone have this working that can help out?&amp;nbsp; Is there something else specific I need to do on the client side?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-local-eap-ldap-authentication/m-p/2916568#M39558</guid>
      <dc:creator>chevymannie</dc:creator>
      <dc:date>2021-07-05T12:03:07Z</dc:date>
    </item>
    <item>
      <title>Scenario 16: Client</title>
      <link>https://community.cisco.com/t5/wireless/wlc-local-eap-ldap-authentication/m-p/2916569#M39559</link>
      <description>&lt;H2&gt;Scenario 16: Client authentication failed on LDAP&lt;/H2&gt;
&lt;P&gt;&lt;A name="_Toc387582670"&gt;&lt;/A&gt;Debug run&lt;/P&gt;
&lt;P&gt;debug aaa ldap enable&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;*LDAP DB Task 1: Feb 07 17:19:46.535: LDAP_CLIENT: Received no referrals in search result msg 
*LDAP DB Task 1: Feb 07 17:19:46.535: LDAP_CLIENT: Received 1 attributes in search result msg 
*LDAP DB Task 1: Feb 07 17:19:46.535: ldapAuthRequest [1] called lcapi_query base="CN=Users,DC=gceaaa,DC=com" type="person" attr="sAMAccountName" user="ish" (rc = 0 - Success) 
*LDAP DB Task 1: Feb 07 17:19:46.535: Handling LDAP response Authentication Failed //Failed auth
*LDAP DB Task 1: Feb 07 17:19:46.536: Authenticated bind : Closing the binded session&lt;/PRE&gt;
&lt;P&gt;&lt;A name="_Toc387582671"&gt;&lt;/A&gt;Workaround&lt;/P&gt;
&lt;P&gt;Check LDAP server for reject reasons.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless/5508-wireless-controller/200072-Cheat-Sheet-Common-Wireless-issues.html#anc18"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5508-wireless-controller/200072-Cheat-Sheet-Common-Wireless-issues.html#anc18&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 01:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-local-eap-ldap-authentication/m-p/2916569#M39559</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2016-05-13T01:15:39Z</dc:date>
    </item>
  </channel>
</rss>

