cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1069
Views
0
Helpful
4
Replies

ACS 5.3 trying to authenticate Macbooks

C8602260424
Level 1
Level 1

Having an issue with Macbook authentication. All Macbooks at this one site, on same switch, going to same RADIUS server, work except for one. Looking at logs it appears server and client never exchange certificates. Attached is log for failed Macbook authentication. Any help is appreciated.

4 Replies 4

Tarik Admani
VIP Alumni
VIP Alumni

Adam,

Do the other macbooks have a machine account in Active directory? If so then this machine doesnt exist in AD. It looks like the client to radius authentication is working, its the issue with ACS to AD not being able to find the machine account:

24433 Looking up machine/host in Active Directory - host/GVLMB009.internal.cigna.com

24437 Machine not found in Active Directory

Thanks,

Tarik Admani
*Please rate helpful posts*

Thanks for the reply. All macbooks are in AD and have machine accounts. The host GVLMB009 had its certificate replaced. Do you think perhaps the AD machine account is corrupt or the shared secret between client and AD no good??

How are the certificates issue? It looks as if the for some reason this ACS is unable to find the machine account. What you can do to troubleshoot this issue is to go the Active Directory Settings then go to attributes, here it will ask you type in a username and you can use GVLMB009$ to see if acs is able to pull the attributes from AD for this account. That will get us started in the troubleshooting process.

Here is a screenshot that will explain what I mean.

Thanks,

Tarik Admani
*Please rate helpful posts*

hkhrais
Level 1
Level 1

Hi Adam ,

Double check the domain name if it's configured on the MACbook also if the machine/computer account is configured correctly on the AD.

Hope This Helps

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: