05-27-2015 08:25 AM - edited 03-10-2019 10:45 PM
Hi,
I need help on these errors.
Here is my setup: WLC 5508 7.6.130.0 -> ACS 5.5.0.46 -> AD 2012
I am getting (2) errors in ACS 5.5
12514 EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain
Already installed the CA cert and local cert in ACS and also in client PC.
Please see screenshots
Solved! Go to Solution.
05-29-2015 09:27 AM
Ok, in this case:
1. You will need to configure the Windows supplicant properly before this can work. You will need to define the type of authentication and the CA certificate to be trusted. If the CA certificate is not available in the list of Certificates then you will need to import it
2. If you are doing PEAP then your Identity Store should be Active Directory and not Certificate Authentication Profile. The Certificate Authentication Profile is used for certificate based (EAP-TLS) authentications.
Thank you for rating helpful posts!
05-27-2015 02:51 PM
Can you attach some screen shots of the supplicant configurations? It looks like you have two issues:
1. Your supplicant is attempting to perform password based (most likely PEAP) based authentication while your Radius server is set to perform Certificate (EAP-TLS) based authentication
2. The authenticating client is not trusting the root CA that issued/signed the Radius certificate
Thank you for rating helpful posts!
05-27-2015 10:58 PM
Hi Neno,
I have not created any wireless profile, so from Windows 7 it is authenticating with PEAP-MSCHAPv2
05-29-2015 09:27 AM
Ok, in this case:
1. You will need to configure the Windows supplicant properly before this can work. You will need to define the type of authentication and the CA certificate to be trusted. If the CA certificate is not available in the list of Certificates then you will need to import it
2. If you are doing PEAP then your Identity Store should be Active Directory and not Certificate Authentication Profile. The Certificate Authentication Profile is used for certificate based (EAP-TLS) authentications.
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide