<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we use only certificate based authentication for user authentication using Cisco WLC with external Radius server in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847817#M5011</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Haydn,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The solution has worked thanks for your help.&lt;/P&gt;&lt;P&gt;I have another query, the radius server expert says that they need 60s to verify the certificate and asked me&amp;nbsp; is there any option in WLC where I have to put timer for this 60s certificate validation.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2019 09:25:21 GMT</pubDate>
    <dc:creator>Afroza Shultana Tonny</dc:creator>
    <dc:date>2019-04-30T09:25:21Z</dc:date>
    <item>
      <title>Can we use only certificate based authentication for user authentication using Cisco WLC with external Radius server</title>
      <link>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3846953#M5008</link>
      <description>&lt;P&gt;I have a cisco WLC 3504 and Ubuntu Radius Server&amp;nbsp; which works as the external Radius server.&lt;/P&gt;&lt;P&gt;I want the wireless clients to be authenticated using certificates and what will be SSID security settings for this?? Is there any documentation link for this??&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3846953#M5008</guid>
      <dc:creator>Afroza Shultana Tonny</dc:creator>
      <dc:date>2021-07-05T17:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use only certificate based authentication for user authentication using Cisco WLC with external Radius server</title>
      <link>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3846982#M5009</link>
      <description>&lt;P&gt;Hi Afroza,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer this&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;&lt;A title="Configure-802-1x-PEAP-with-FreeRadius" href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211263-Configure-802-1x-PEAP-with-FreeRadius.html" target="_blank" rel="noopener"&gt;Configure-802-1x-PEAP-with-FreeRadius&lt;/A&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 08:18:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3846982#M5009</guid>
      <dc:creator>Sathiyanarayanan Ravindran</dc:creator>
      <dc:date>2019-04-29T08:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use only certificate based authentication for user authentication using Cisco WLC with external Radius server</title>
      <link>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847007#M5010</link>
      <description>&lt;P&gt;Effectively the you need to do following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add the RADIUS server to the WLC&lt;/P&gt;&lt;P&gt;Configure the WLAN for WPA2 Enterprise 802.1x authentication AS per the WLC parts of this document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where it goes through ISE configurations you need to configure your RADIUS server to EAP-TLS&lt;/P&gt;&lt;P&gt;Here is how FreeRADIUS does it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Configure_freeradius_to_work_with_EAP-TLS_authentication" target="_blank"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Configure_freeradius_to_work_with_EAP-TLS_authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 09:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847007#M5010</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-04-29T09:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use only certificate based authentication for user authentication using Cisco WLC with external Radius server</title>
      <link>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847817#M5011</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Haydn,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The solution has worked thanks for your help.&lt;/P&gt;&lt;P&gt;I have another query, the radius server expert says that they need 60s to verify the certificate and asked me&amp;nbsp; is there any option in WLC where I have to put timer for this 60s certificate validation.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 09:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847817#M5011</guid>
      <dc:creator>Afroza Shultana Tonny</dc:creator>
      <dc:date>2019-04-30T09:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can we use only certificate based authentication for user authentication using Cisco WLC with external Radius server</title>
      <link>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847838#M5012</link>
      <description>&lt;P&gt;Glad i could help, make sure you help others out by marking solutions as accepted solutions.&lt;/P&gt;&lt;P&gt;Around timeouts, 60 seconds is a very long time, from a client prospective it it takes 60 seconds to authenticate i'm giving up or logging a ticket. Normally if the RADIUS server is in the same network segment as the WLC then for TLS I have never seen requirement to go past 5 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-0/configuration-guide/b_cg80/b_cg80_chapter_01010.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-0/configuration-guide/b_cg80/b_cg80_chapter_01010.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are also some best practices for EAP style authentications here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/118703-technote-wlc-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/118703-technote-wlc-00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 10:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-we-use-only-certificate-based-authentication-for-user/m-p/3847838#M5012</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-04-30T10:06:27Z</dc:date>
    </item>
  </channel>
</rss>

