Showing results for 
Search instead for 
Did you mean: 

PEAP and ACS5 server side certificate question

dan hale

Hello All, I'm in the process of setting up PEAP with ACS 5. From understanding the certificate that I generate is a server side certificate used between ACS and CA authority. However, according to the Cisco document that I'm using it sounds like I still have to install a certificate on the wireless clients that validate the server certificate.

Is there a process to push this cert out via AD or do I need to manually install it and if I wanted can I get away with out checking the validate the server certificate on the wireless client?

see Configure the Wireless Network Connection

step number 12.



4 Replies 4

Peap mschapv2 requires only a server side cert.

If you do eap-tls then server and client side is needed

Remember the cert you generate should be signed my a major ca, just in case you validate the cert on the clients .

Make sense ?

Sent from Cisco Technical Support iPhone App

"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin

Thanks, George.

I guess what I was getting confused based on the below picture I was thinking that when I validate the server side cert that I would also need to install the cert on the client under "trusted root certification authorities".

I realize now that all we are doing based on the picture is validating the server side cert and saying we are using this particular CA trusted root authority. In this example it is "ca.demo.local"

Is it really necessary to validate the server certificate on the client? What are the issues if I do not?



Eric Lindsey

We are using Peap with ACS and are mot using a client side cert. our server side cert is from Entrust.

Sent from Cisco Technical Support iPhone App

Scott Fella
Hall of Fame Guru Hall of Fame Guru
Hall of Fame Guru

You should validate the server cert or else your clients will trust any certificate. This will help prevent a man in the middle attack.

Sent from Cisco Technical Support iPhone App

*** Please rate helpful posts ***
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers