07-13-2008 05:43 PM - edited 03-10-2019 03:58 PM
We deployed ACS 4.0 (NOT ACS SE) and WLAN in our corporate network.
Our ultimate goal is to have each staff authenticated against our AD via ACS.
We managed to get PEAP working successfully, but failed with EAP-TLS.
From the log we noticed that when PEAP is used, ACS forward username to AD in domain-qualified format (domain\user),and authentication is successful.
When EAP-TLS is used, ACS forward username to AD in UPN format (user@domain), and ACS received "cannot get user account controler for user@domain" from windows database, authentication failed. Any workaround for this?
Can anyone throw some light here?
Thank you.
Lahki
07-14-2008 08:14 AM
What supplicant are you using? If you can configure it to send the EAP outer-id in a different format (e.g. just "username" or even "anonymous"), then you should avoid this problem. Otherwise, you'll probably need to upgrade to ACS 4.2.
Shelly
07-14-2008 08:39 PM
I am using Trapeze wirelesss gears.
07-15-2008 08:10 AM
Okay, but your PC still has to have a supplicant. If there's no way to change the format of the EAP outer-id in your supplicant, you'll need to upgrade your ACS. If you have access to bug toolkit, look up CSCsk49811.
Shelly
07-15-2008 03:39 PM
Not sure what you mean by supplicant.
All the laptops are running XP. Is it possible to change the outer-id for XP supplicant? How?
Thank you in advance.
07-20-2008 03:50 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: