×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

TLS Handshake fails on Mac OS X

Unanswered Question
Oct 10th, 2013
User Badges:

Hello,


We have a problem with the authentication of Mac OS X 10.8 devices on our wireless network. We are using ISE version 1.2 with patch 2 and a 2504 with version 7.4.115 as WLC. The device should be authenticated with a client certificate over eap-tls.


In general this setup works fine. But we have problems with two Macs which don’t finish the TLS handshake for authentication. ISE shows “5440 Endpoint abandoned EAP session and started new“ as error message. The Client log shows a missing or not completely received server certificate.
We also made several traces to find the point at which the server certificate gets lost. But actually the client receives the complete server hello from the tls handshake and simply doesn’t respond.


Finally we found the problem in this case. It was the Bluetooth connection to an Apple magic mouse. After deactivating the Bluetooth connection the authentication works fine. When the connection is established you can reactivate Bluetooth. But this is more a workaround than a solution.
Also interesting is the fact that it doesn’t work with this specific controller but it works fine with another one with almost identical configuration.
We got a hint from an apple specialist that changing the channel might help because of interference but it makes no difference.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Matthew Hines Thu, 11/07/2013 - 08:02
User Badges:

We are also recently having pretty much the same issue; however, our issue is with Apple IPods, IPads, and IPhones. Using EAP-TLS, Cisco WLCs 5508s running 7.4.110. Have a tac case open now trying to re-duplicate the issue. It seem in previous versions maybe 1.2 patch 1, I didn't notice the failures as often? Not sure. Any help in answering this question would be helpful.

Philip Vilhelmsson Thu, 11/14/2013 - 00:53
User Badges:

I am experiencing the same problem on one PC. Have to do a spectrum sweep to see if it is a bluetooth problem.


Matthew did you find a solution together with TAC?

hermodfinjord Tue, 11/19/2013 - 03:50
User Badges:

Hi

I have the same problems with a viritual WLC and ISE v1.2. Windows 7 clients cant connect to their WLAN and the ISE log fills with authentication error messages.


5440 Endpoint abandoned EAP session and started new


Have you heard anything from TAC?


Actions

This Discussion