I have a customer that evaled an earlier release (3.0 or earlier) of ACS and did not implement in their network. They are now in the planning stages of Wireless and dot1x in thier campus. One of their major concerns with ACS has to do with the integration with Windows AD. They claim that in their trial, ACS did not pass back illegal password messages to the client machine. In other words, if a user entered a password that did not match policy a notification was never recieved by the user and therefore did not realize their password had not been changed. I cannot find where this is/was a known problem and whether or not it has been corrected in subsequent releases of ACS. Any information would be greatly appreciated