Using WLC 126.96.36.199 with a WPA / 802.1x SSID, backing off to ACS SE v4.1, which backs off to Win2k3 domain.
The SSID utilises the AAA Override function, which is used to apply Access Control Lists. The ACLs change dependent upon whether a Machine Account or User Account is used to log in.
All of this works brilliantly with PEAP-MSCHAPv2, but when EAP-TLS (using machine cert / user smartcard) is used, the ACL doesn't seem to change.
ACS logs the authentication as being successful in both circumstances, and both EAP types are allowed on ACS, so I'm thinking that either;
(A) There's a bug on ACS?
(B) That the WLC is misbehaving?
Finally, is there a WLC command that allows me to see what ACLs are actually applied to what user? This would allow me to see if the WLC is actually changing the ACL, or not.