07-21-2014 10:40 AM - edited 02-21-2020 05:14 AM
Hi,
I have a ISE certifiacte issue when I try to authenticate wireless user with ISE. He show me this:
12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate
Please can you help me?
Regards
Aristide
07-21-2014 07:07 PM
what type of client it is? if windows , please opt out option < validate server certificate > from Wireless adapter properties
07-22-2014 03:25 AM
Hi Salodh,
It is a Windows client.
07-21-2014 08:27 PM
This pretty much means that the authenticating client is not trusting the certificate that is installed in ISE. That certificate is used to build the EAP tunnel that would be used to pass the PEAP credentials. So a couple of questions:
1. What certificate do you have installed in ISE for EAP?
2. What certificate is the supplicant set to trust
07-22-2014 03:20 AM
Hi Neno,
I have installed the Windows server 2008R2 certificate, the supplicant is set tç trust to Root-CA certificate.
Regards,
Aristide
07-22-2014 04:47 AM
06-18-2015 02:02 AM
supplicant or client machine is not accepting the certificate from Cisco ISE. make sure cert is usage is selected for EAP, expiry date, checked default allowes protocols on ISE, validate server certificate is not selected.. set it to trust the ISE certificate . you can try to remove wireless network profile and recreate
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide