cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
697
Views
0
Helpful
4
Replies

PEAP authentication failure with ACS 3.3.1

nuno.santos
Level 1
Level 1

Hi,

whenever i try to authenticate a user through peap, and after installed the certificate and activate peap support, i obtain the following failed attempt message:

EAP-TLS or PEAP authentication failing during SSL handshacke.

Anybody knows how to solve it?

Thanks

Nuno Santos

4 Replies 4

irisrios
Level 6
Level 6

EAP-TLS authentication using Active Directory fails when Cisco Secure ACS runs on a member server. To perform EAP-TLS authentication using Active Directory as the external user database, Cisco Secure ACS must run on a domain controller.

For additional info:

http://www.cisco.com/en/US/products/sw/secursw/ps2086/prod_release_note09186a00801bfd95.html#1204438

Hi,

Peap uses mutual authentication by server certificate and client credential. You have the error because you didn't download correctly the server certificate to the client.

Bye

Stefano Furno

I'm also trying to impliment PEAP with ACS/Safeword Token server. We generated a self signed certificate on the ACS server, This certificate must be installed on our clients? I was under the impression the certificate would be exhanged.

gabor.varga
Level 1
Level 1

Hi!

I received this error message when my client refused accepting the (non public) certificate of the ACS installed on.

I had to set my client not to verify ACS's certificate or to install its certificate in the Windows certificate store.

This solved the problem above.

Good luck!

Gabor