02-10-2013 05:30 PM - edited 07-03-2021 11:30 PM
Hello All, I'm in the process of setting up PEAP with ACS 5. From understanding the certificate that I generate is a server side certificate used between ACS and CA authority. However, according to the Cisco document that I'm using it sounds like I still have to install a certificate on the wireless clients that validate the server certificate.
Is there a process to push this cert out via AD or do I need to manually install it and if I wanted can I get away with out checking the validate the server certificate on the wireless client?
see Configure the Wireless Network Connection
step number 12.
Thanks,
Dan
02-10-2013 05:34 PM
Peap mschapv2 requires only a server side cert.
If you do eap-tls then server and client side is needed
Remember the cert you generate should be signed my a major ca, just in case you validate the cert on the clients .
Make sense ?
Sent from Cisco Technical Support iPhone App
02-11-2013 06:29 PM
Thanks, George.
I guess what I was getting confused based on the below picture I was thinking that when I validate the server side cert that I would also need to install the cert on the client under "trusted root certification authorities".
I realize now that all we are doing based on the picture is validating the server side cert and saying we are using this particular CA trusted root authority. In this example it is "ca.demo.local"
Is it really necessary to validate the server certificate on the client? What are the issues if I do not?
Thanks,
Dan
02-11-2013 04:30 PM
We are using Peap with ACS and are mot using a client side cert. our server side cert is from Entrust.
Sent from Cisco Technical Support iPhone App
02-11-2013 06:34 PM
You should validate the server cert or else your clients will trust any certificate. This will help prevent a man in the middle attack.
Sent from Cisco Technical Support iPhone App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide