<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC EAP-TLS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102123#M44394</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Philip,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Actually the setting is working for Laptops only issue with Wireless IP Phones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the logs from Cisco ACS. I followed the deployment guide for IP Phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 0000 1756 0xb CryptoLib.SSLConnection.pvServerInfoCB - Process TLS&amp;nbsp; data: &lt;STRONG&gt;SSL state=SSLv3 read&amp;nbsp; client certificate A&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 2009 1756 0xb &lt;STRONG&gt;EAP: EAP-TLS:&amp;nbsp; Handshake failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 E 2255 1756 0xb &lt;STRONG&gt;EAP: EAP-TLS:&amp;nbsp; ProcessResponse: SSL recv alert fatal:bad certificate&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 E 2258 1756 0xb &lt;STRONG&gt;EAP: EAP-TLS:&amp;nbsp; ProcessResponse: SSL ext error reason: 412 (Ext error code =&amp;nbsp; 0)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 E 2297 1756 0xb EAP: EAP-TLS: &lt;STRONG&gt;ProcessResponse(1519):&amp;nbsp; mapped SSL error code (3) to -2198&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 0526 1756 0xb EAP: EAP-TLS: &lt;STRONG&gt;Unknown EAP code&amp;nbsp; Unknown EAP code&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 0366 1756 0xb EAP: EAP state: action = send&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 1151 1756 0xb [AuthenProcessResponse]:[eapAuthenticate] returned&amp;nbsp; -2198 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 1198 1756 0xb EAP: &amp;lt;-- EAP Failure/EAP-Type=EAP-TLS (identifier=7,&amp;nbsp; seq_id=7)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 5501 1756 0xb &lt;STRONG&gt;Done&amp;nbsp; UDB_SEND_RESPONSE, client 50, status&amp;nbsp; UDB_EAP_TLS_INVALID_CERTIFICATE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt; Nibin Rodrigues&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Feb 2013 06:16:22 GMT</pubDate>
    <dc:creator>nibinrodrigues</dc:creator>
    <dc:date>2013-02-13T06:16:22Z</dc:date>
    <item>
      <title>WLC EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102121#M44392</link>
      <description>&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;My Wireless network consists of 8 WLC and 2 Cisco ACS 1113 with 4.2. I need to implement certificate authentication for Cisco Wireless Phone SSID. I tried PEAP along with certificate generated by Microsoft Cert Server, but the issue is the client can ignore the certificate and I believe only way to force is via Active Directory group policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;So as my Cisco IP Phones are not joined to Active Directory I think the only option is to use EAP-TLS. For this I have the following Queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;•1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What will be the SSID security setting. ( I tried Layer 2 802.X with WEP 104bit encryption)&lt;/LI&gt;&lt;LI&gt;•2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Do I need to install any certificate on WLC if yes which Certificate (Ex root, Client)&lt;/LI&gt;&lt;LI&gt;•3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What Certificate should be installed on Client.&lt;/LI&gt;&lt;LI&gt;•4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What should be the client PC security setting for EAP-TLS&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I had gone through the following Docs for reference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a008068d45a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a008068d45a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-24723" target="_blank"&gt;https://supportforums.cisco.com/docs/DOC-24723&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nibin&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102121#M44392</guid>
      <dc:creator>nibinrodrigues</dc:creator>
      <dc:date>2021-07-04T06:23:12Z</dc:date>
    </item>
    <item>
      <title>WLC EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102122#M44393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Layer 2: WPA+WPA2, WPA2 Policy check, WPA2 Encryption checked, Authenticatin Key management: 802.1X.&lt;/P&gt;&lt;P&gt;2. You only need intermediate CA cert and device cert for WLC. You probably don't need root cert since your clients will have this, but it won't hurt to have it.&lt;/P&gt;&lt;P&gt;3. A device/machine certificate and the root cert.&lt;/P&gt;&lt;P&gt;4. Make a wlan-profile that with the setting to use certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2013 15:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102122#M44393</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-02-12T15:20:00Z</dc:date>
    </item>
    <item>
      <title>WLC EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102123#M44394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Philip,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Actually the setting is working for Laptops only issue with Wireless IP Phones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the logs from Cisco ACS. I followed the deployment guide for IP Phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 0000 1756 0xb CryptoLib.SSLConnection.pvServerInfoCB - Process TLS&amp;nbsp; data: &lt;STRONG&gt;SSL state=SSLv3 read&amp;nbsp; client certificate A&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 2009 1756 0xb &lt;STRONG&gt;EAP: EAP-TLS:&amp;nbsp; Handshake failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 E 2255 1756 0xb &lt;STRONG&gt;EAP: EAP-TLS:&amp;nbsp; ProcessResponse: SSL recv alert fatal:bad certificate&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 E 2258 1756 0xb &lt;STRONG&gt;EAP: EAP-TLS:&amp;nbsp; ProcessResponse: SSL ext error reason: 412 (Ext error code =&amp;nbsp; 0)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 E 2297 1756 0xb EAP: EAP-TLS: &lt;STRONG&gt;ProcessResponse(1519):&amp;nbsp; mapped SSL error code (3) to -2198&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 0526 1756 0xb EAP: EAP-TLS: &lt;STRONG&gt;Unknown EAP code&amp;nbsp; Unknown EAP code&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 0366 1756 0xb EAP: EAP state: action = send&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 1151 1756 0xb [AuthenProcessResponse]:[eapAuthenticate] returned&amp;nbsp; -2198 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 1198 1756 0xb EAP: &amp;lt;-- EAP Failure/EAP-Type=EAP-TLS (identifier=7,&amp;nbsp; seq_id=7)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;AUTH 02/10/2013&amp;nbsp; 13:29:58 I 5501 1756 0xb &lt;STRONG&gt;Done&amp;nbsp; UDB_SEND_RESPONSE, client 50, status&amp;nbsp; UDB_EAP_TLS_INVALID_CERTIFICATE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt; Nibin Rodrigues&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 06:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102123#M44394</guid>
      <dc:creator>nibinrodrigues</dc:creator>
      <dc:date>2013-02-13T06:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: WLC EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102124#M44395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you gone through the 7925 configuration doc?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/docs/voice_ip_comm/cuipph/7925g/7_0/english/administration/guide/7925cfgu.html#wp1376129" target="_blank"&gt;http://www.cisco.com/en/US/docs/voice_ip_comm/cuipph/7925g/7_0/english/administration/guide/7925cfgu.html#wp1376129&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 08:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102124#M44395</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-02-13T08:18:23Z</dc:date>
    </item>
    <item>
      <title>WLC EAP-TLS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102125#M44396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS worked but IP Phone disconnecting while roaming. Any advicesss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nibin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 11:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-eap-tls/m-p/2102125#M44396</guid>
      <dc:creator>nibinrodrigues</dc:creator>
      <dc:date>2013-03-04T11:46:25Z</dc:date>
    </item>
  </channel>
</rss>

