cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1346
Views
0
Helpful
6
Replies

ACS 5.2, WLC 7.0.98.0, Certificate Authentication

Kayle Miller
Level 7
Level 7

I have revised this post.

The inital EAP issue was that the client was rejecting the server certificate and it turned out to be a mis-spelling in the certificate on the ACS appliance, but now that this has been resolved I am getting the error that the user is not found in the selected identity store. The user it's trying to authenticate is the computer name against active directory; the computer is a member of the domain and the groups are setup properly. I am using the active directory connector not an ldap connection.

I have seen numerous posts that were similar and the majority of them have no resolution; there has to be something simple being missed, can anyone provide details.

Thanks.

6 Replies 6

bbxie
Level 3
Level 3

it seems the client had not installed the CA certificate which is used to validate ACS' server certificate, so get the CA cert and install it in the client.

The certificate was installed but there was a mis-spelling

What error are you seeing in the ACS failed attempts. Are you doing machine and user authentication?  I would always try to do user authentication first and make sure that works then do machine authentication if that is what you eventually want to do. I have had issues like yours, but it was how the client was setup.

Posted from my mobile device.

-Scott
*** Please rate helpful posts ***

It tells me the user is not found in active directory when it attempts to authenticate the computer or the user, yet everything looks formatted correctly. PEAP works but straight EAP-TLS does not.

One thing to check is under the global authentication, make sure you only check what authentication you are using.  Uncheck all the rest.  Verify the windows setup also... see if the CA is listed under the Trusted Root CA, or else uncheck the Validate Server checkbox.

-Scott
*** Please rate helpful posts ***

To troubleshoot it, you need to provide more information, for example:

1. Your configuration screenshot

2. the Radius log, click detail of the failing log, copy and paste all the steps happened for the failed Auth

3. ACS build #

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card