Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PEAP set up

Does anybody have experience setting up PEAR with ACS in Windows environment? I really got headache.

I used CA services in Windows issue 2 user certificates to a user account and a computer (XP with SP2). Then I issued a certificate to ACS. I also installed the CA root to ACS. I think I did everything following Cisco document. However, I got "EAP-TLS or PEAP authentication failed during SSL handshake"

in failed attempts log and

"PEAP: ProcessResponse: SSL handshake failed, status = 3 (SSL alert fatal:certificate unknown)"in CSAuth logs.

Have worked on this issue for 2 weeks but no clue at all. Please help me out.

5 REPLIES

Re: PEAP set up

Sky,

SSL handshake points out to certificate issue. Please uncheck validate server cert on suplicant and then try to connect.

Find attached the peap guide

Regards,

JG

New Member

Re: PEAP set up

Hi

I got the same problem (ACS 4.1)

Unchecking validate server cert makes it working.

But this way clients will accept any server certificate, i.e. man in the middle will be possible !

Is there a way to solve the probleme ?

Re: PEAP set up

I don?t think MIM is possible. Even if you do not check validate server certificate. In PEAP, still supplicant uses the certificate offered by Server as to create an SSL tunnel.

Validating server certificate is just an additional security, where you ensure that you are connecting to correct Radius server, if you have many in your network...

Regards,

Prem

Re: PEAP set up

And to get correct the SSL handshake,

Ensure that we have *also* installed the root certificate, from "ACS Certification Authority Setup" and checked that root certificate from where ACS's server certificate was issued in "Edit Certificate Trust List"

Regards,

Prem

New Member

Re: PEAP set up

Thanks man!

218
Views
10
Helpful
5
Replies