Re: Can't seem to get 802.1x to work



Okay, I managed to get PEAP working now after some painful
troubleshooting but now am getting this message when a machine tries to
authenticate:

EAP-TLS or PEAP authentication failed during SSL handshake

From Cisco it tells me that the certificate on the client end is
invalid. What does that mean? Do I have to manually install the
certificate generated for my ACS server into each client machine with
802.1x enabled?

psychogenic wrote:
Hey all, I'm trying to setup 802.1x using PEAP authentication. I have
the following setup in my lab:

2003 Server running SecureACS 4.0 with CA installed
a 3550 Cat switch running 12.2 SEE IOS
a Windows XP SP2 laptop with 802.1x authentication enabled

The problem is I can not choose PEAP settings on SecureACS because it
keeps giving me an error that a certificate has not been installed even
though I have installed it. I followed this guide here:

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml#acs-1

and here

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a008052e963.html#wp326973

pretty much to the E, and still no luck. I install the certificate, and
it tells me its been installed and to restart the ACS service, and I
get the same error message saying it's not been installed.

Has anyone seen this before?

.



Relevant Pages

  • Re: PEAP-TLS vs EAP-TLS
    ... It covers the deployment of PEAP with digital certificates (what you are ... PEAP-TLS as MS docs pretty much all were about PEAP-MSCAHPV2 or generally ... Of course user certificate authentication used in PEAP-TLS ...
    (microsoft.public.windows.server.security)
  • Re: PEAP-TLS vs EAP-TLS
    ... and PEAP is that PEAP is a two-step process where 1) the RADIUS server is ... authenticated to the client via the RADIUS server's certificate, ... encrypted TLS channel is set up for 2) client authentication (either using ... But I wonder how much more secure PEAP-TLS is than EAP-TLS, ...
    (microsoft.public.windows.server.security)
  • RE: PEAP based 802.1x LAN authentication
    ... Authentication, EAP Methods. ... Do you have PEAP added here? ... edit and make sure the certificate that you want to use is selected. ... the server certificate is now stored in "Personal " ...
    (Focus-Microsoft)
  • Re: Certificates/SSL Connections From Behind ISA
    ... but I can't seem to get the certificate from the ... for web chaining to work that way you don't install a server ... actually install a client certificate used for authentication to the ... Did you install Sun's JVM, ...
    (microsoft.public.isaserver)
  • Re: Mobile 2003 Radius authentication requirements
    ... So where does the cert com from "using TLS"? ... So you are saying that IAS creates its own Certificate ... order to use 802.1x RADIUS authentication on Mobile 2003 PPC. ... unless I install a personel certificate on ...
    (microsoft.public.internet.radius)