hello,
I have following configuration:
Catalyst 2950G-proximity switches with IOS 12.1(19)EA1c.
Cisco Secure ACS Appliance 3.2.3.11
SunONE Directory Server ldap server version 5.2_Patch_2
I am trying to setup 802.1x authentication for wired and wireless (aironet) clients, with VLAN parameter provided by using group mapping with ldap groups.
I understand that the best for that will be EAP-GTC version of PEAP.
I tried (for a week now!!!) to install the certificate in order to activate PEAP on ACS.
I carefully read and re-read following documents:
http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/csapp32/user/sau.htm
and this one
http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_configuration_example09186a008020a45c.shtml
I setup three times a CA using "Microsoft Certificate Services" and OpenSSL. I am positive that Ive done it correctly since each time CA certificate installation worked and each time I found the the CA in the "Certificate Trust List"
The procedure to install the certificate:
1. Install the CA certificate on ACS server (through ftp)
2. Create the Certificate Signing Request and paste in Notepad to make the private key file
3. Paste the Certificate Signing Request into the "base64 encoded PKCS#10..."
4. Get the Server Certificate after issuing and put along with private key file on the ftp server.
When trying to install I get that
"Unsupported private key file format."
message.
The private key file IS the Certificate Signing Request past-ed in a file, Isnt it?!?
I have done that many times. I tried many names and extensions for files. I tried to overcome the UNIX and DOS representation for CR and LF in text files.
Each time the same error message.
same problem like in this thread:
http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1dd61919
Everybody, please help, !!!!