Cisco AAA/Identity/Nac :: CRL Validation Fails On ACS 5.2.0.26.3

Aug 11, 2011

We are using ACS v5.2.0.26.3 in 802.1X certificate based authentication. Now, when we added CRL functionality into ACS it fails in CRL validation and gives following error message:
 
LastErrorMessage=CRL PKI verification failed
Certificate Revocation list [URL]
 
We have installed root, device and server certificates from CA, but for management we are still using self-signed certificate.
 
Question is, which certificate is used when validating downloaded CRL file - one used for EAP-TLS or one used for management interface?
 
How I can check which certificate ACS server is using for CRL validation?

View 19 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: ACS 5.x Identity Store Sequence And Token Validation

Dec 3, 2012

We have a ACS 4.3.2 installed with users authenticating against an Active Directory database. The AD database not only authenticate the users but also assigns the group that is used to select IP address pool.Now the requirements require to use token authentication with SafeNet. This authentication uses the same username but the password is composed of the original password + OTP.The problem is that the SafeNet server doesn't return the group membership.I've read about the Identity Store Sequence in ACS 5.x and I think I could use it in the following sequence:! configure an Authentication Sequence using the SafeNet token server (this works with ACS 4.x)I configure an Attribute Retrieval Sequence against the AD database. This would use the username only, no password and would retrieve the group membership.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Posture Validation On ACS 5.3?

Sep 9, 2012

it's possible to enable Posture validation on ACS 5.3. If so, could I have a link or a procedure for implementation ?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5 Certification Validation

Jul 2, 2012

I want ACS 5 to authenticate the wireless users validating each user with a certificate. The ACS is connected to the AD but, is it possible to do that using user/password from the certificate?, i need to do that with certificate and independant of the AD certificates of each user, so it will be scalable.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Testing OCSP Servers For Certificate Validation On ACS 5.4

Mar 14, 2013

I'm currently having issues testing OCSP servers for certificate validation on ACS 5.4. Server team claims everything is fine on their side, but all attempts result in the following error:12562  OCSP server response is invalid
 
I've already tried to disable NONCE extension support and signature validation, which hasn't really had any effect. How to debug OCSP processing or look into the problem more precisely another way?

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Import Template Gives File Format Validation Failed

Sep 21, 2011

Network Resources - Network Devices and AAA Clients- File Operations - Add - gives me File Format Validation Faliled. I am carefull to leave the header as it is. The header in the Import Template looks faulty, see attached. When exporting devices I also get the same header as attached. I also tried to change the header so its all in one column, but with same result.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: %ASA-3-717009 / Certificate Validation Failed / Certificate Date Is Out-of-range

Jan 30, 2012

There is ASA with remote access VPN and users are authenticated using third party signed certificates (CA is not local in ASA).When user certificate expires i can see it in syslog messages. For example:
 
     %ASA-3-717009: Certificate validation failed. Certificate date is out-of-range, serial number: (...)
 
I would like to know if there is an opportunity to view user's certificate expiry date beforehand, say, 3 days before?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Upgrade ACS 5.3 To 5.4 Fails

Dec 6, 2012

I try  upgrade ACS 5.3.0.40 to new version 5.4.0.46. Everything looks ok:
 
ACS-machine/acsadmin# application upgrade ACS_5.4.0.46.tar.gz rep01 Do you want to save the current configuration ? (yes/no) [yes] ? Generating configuration. Saved the running configuration to startup successfully
 
% CARS Install application required post install reboot...
 
Broadcast message from root (pts/0) (Thu Dec  6 23:36:41 2012):
 
The system is going down for reboot NOW!
 
Application upgrade successful 
 
But ACS machine (vmware instance) can't boot with this result: Volume group "smosvg" not found. (for details see attachment)

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ISE Upgrade Fails From 1.1.0 To 1.1.2.145

Jan 30, 2013

I am trying to upgrade ISE from 1.1.0 to 1.1.2.145 but failed. Find the details below.
 
DR-ise-pdp-01/admin# application upgrade ise-appbundle-1.1.2.145.i386.tar.gz ISE1
Save the current ADE-OS running configuration? (yes/no) [yes] ?

Generating configuration...
Saved the ADE-OS running configuration to startup successfully
Initiating Application Upgrade...
Stopping ISE application before upgrade...
Running ISE Database upgrade...
% Application upgrade failed. check logs for more details.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 AD Join Fails

Sep 11, 2011

I am trying to join my ACS 5.1 to my AD.  In the External Identity Stores > Active Directory I have put in the AD administrator details and hit the test button and the test succeeds.
 
However, when I try to save changes it fails with an eror saying it can't connect to the LDAP server.
 
Error while configuring Active Directory:Error while configuring Active Directory:Unexpected LDAP Error Can't contact LDAP server  due to unexpected configuration or network error.Please try the --verbose option or run 'adinfo --diag' to diagnose the problem.Join to domain 'Mydomain.local', zone 'null' failed.
 
I have done this lots of times and never had any issue once the test connection succeeds.
 
I've checked the time and timezones on both ACS and AD and they are the same.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Csv Import Fails

Dec 6, 2010

I'm trying the csv file import and getting some errors.
 
010-12-07 14:23:47: File Format Validation Completed2010-12-07 14:23:47: Import Started

2010-12-07 14:23:47: Record number: 1, Host 01-02-03-04-05-06: Import Failed2010-12-07 14:23:47: null Import process failed for unexpected reason: Unknown error has accurred.2010-12-07 14:23:47: Import Completed With errors

-------- Summary --------Total Number of Records Processed:1Number of Records Failed:1Number of Records Imported:1---------- End ----------Please refresh the table to see the changes.
 
On some other tries I get null field or missing fields.
 
It actually creates the host, but on editing it I get the following message:
 
An unexpected error has occurred. To continue your work, reselect the option in the left navigation bar.If you continue to receive the unexpected error message, close your browser and log in to ACS again.If you still receive the unexpected error message, contact your system administrator or technical assistance.
 
MACAddress:String(64):Required,description:String(1024),"enabled:Boolean(true,false):Required",HostIdentityGroup:String(256),VLAN:String(256):Required,attr-Expiration Date:Date(yyyy-Mmm-dd)01-02-03-04-05-06,AAATest,true,,Guest,2010-Dec-08

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 EAP-TLS Re-authentication Fails

Jan 21, 2013

I configured WiFi connection on Windows XP and Windows 7 with EAP-TLS (using Cisco WLC 7.0.235.3 and Cisco ACS 5.2.0.26.10). It is configured with computer authentication and computers certificates are autoenrolled from Microsoft PKI.It works well!
 
Now I configured Windows 8 with same configuration.First authentication works but if I manually disconnect and reconnect, I got this error on ACS: 22047 Principal username attribute is missing in client certificate.In EAP packets, we could see that Windows 8 sent a TLS session ticket but session was not resumed correctly by ACS..On ACS configuration, we checked this option "Enable EAP-TLS Session Resume" with session timeout "7200".

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Cat 3560G With IOS 12.2SE Fails Authorization To MS IAS

Jun 8, 2011

I have IAS set up on my organization's AD domain controller.  Multiple policies set up for various authorization scenarios, authenticating based on Windows user groups and client IP, authorizing by passing "shell:priv-lvl=#" where #=desired privilege level.  On my IOS devices I have:[code]
 
This identical configuration operates correctly on a Cisco 3825 and a Catalyst 4506.  On the 24 port Cat 3560G PoE running 12.2SE (do not recall exact IOS version, but I know it is in that release train) that I am currently working on, every attempt to login via ssh passes authentication but fails authorization, displaying %Authorization Failed on the terminal and a message stating that "No appropriate privilege level found for user" in the debug statement from RADIUS.I have verified correct server addresses, correct source-interfaces, and that configs between the three devices match exactly with regards to aaa.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Patch Rollup For Secure ACS 4.2 Fails?

Jan 7, 2010

I've got 2 freshly installed ACS 4.2 for Windows servers and I need to apply the latest patch rollup before I build the configurations.  I stopped the ACS services and ran Acs-4.2.0.124.15-SW.exe to install the patches.  The application begins running fine but fails on upgrading the database and then none of the ACS services would start.  I was able to restore the files from the backup that runs with the patch utility and get ACS functioning again.  What am I missing - does the patch rollup require any specific Microsoft Patches to be installed or something like that?

View 7 Replies View Related

Cisco AAA/Identity/Nac :: WS-C2960G-48TC-L - 802.1x Fails To Authenticate

Nov 13, 2012

I have a user named "testuser" and trying to authenticate from the xp computer but fails to authenticate. The ACS logs says that authentication failed, the user is in the local database but why it fails to authenticate?

I have cisco switch :

WS-C2960G-48TC-L   12.2(52)SE            C2960-LANBASEK9-M

*Mar  8 04:03:55.030: AAA/BIND(00000029): Bind i/f 
*Mar  8 04:03:55.173: %AUTHMGR-5-START: Starting 'dot1x' for client (782b.cbc9.a027) on Interface Gi0/2 AuditSessionID 0A6A00200000001924EBD428
*Mar  8 04:03:57.010: %LINK-3-UPDOWN: Interface GigabitEthernet0/2, changed

[Code]....

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 To Use Local Database When LDAP Fails

Mar 22, 2011

i'm trying to configure acs 5.2 to LDAP external idenity store, when LDAP failes ACS 5.2 should use internal indenity store. I configured A sequence to use LDAP 1st then Internal and i shut off the link to the LDAP but ACS will not use internal,  AAA Diagnostics keeps telling me that Cannot establish connection with LDAP server and will not use the internal store.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Migration Utility Fails On ACS 4.x Server ID?

Dec 21, 2010

I am working through the migration from ACS 4.1.4 on Windows Server 2003 to ACS 5.2 on the appliance.  I have created the 4.1.4 migration server, installed the software and imported the data from our production ACS 4.1.4 box.  I downloaded the migration utility from the 5.2 ACS server and am attempting to run on the 4.1.4 migration server.  The question that fails is:
 
Enter ACS 4.x Server ID:
 
I do not know what this means and do not see anything on the 4.1.4 server that identifies the Server ID.  I try localhost and it does not work and the 4.1.4 server is not registered in DNS or I would try that  (and . are not valid characters in the ID so the IP does not work).
 
How have other people handled this question?  Is there something that can identify the local server ID?

View 9 Replies View Related

Cisco AAA/Identity/Nac :: ISE 1.1 Change Password On Next Log On Fails On IPhone / IPad

Apr 29, 2012

We're in the process of implementing an ISE 1.1 server for Guest Wireless Access / BYOD at our company and ran into an issue with authenticating from iPhones / iPads when the account is set with 'change password on next logon' (it's a local account created on the ISE server - not AD). It fails and displays 'unable to join network' on the iPhone. The ISE log shows a '5411: No response received in 120 seconds'. We're able to authenticate from Windows devices and are prompted to change the password during the authentication process. If we unchecked the 'change password' box we can authenticate from iPhones & iPads without any issue but we need to have a way for users to set their own password.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - LDAP Authentication Works / Authorization Fails

Oct 24, 2011

I set up LDAP store pointing to a Windows domain and am testing authenticating users via an ASA.  In my LDAP config, its set for "Groups Objects refer to subjects" and I selected usernames in the drop down.  I also added a a Global Group to the Directory groups tab in the LDAP store that I created.
 
Under my Access Polices, I created a rule that meets two condititons - coming from the ASA, and then I was able to select the group from the drop down box for my ldap domain.  As a condition, it shows up as DomainName:External Groups.  I set the permission to Permit Access.
 
Originally, I was failing authentication and I was receiving Subject Not Found in Store.  I adjusted the Identity Sequence and now I receive a the following error:
 
15039:  Selected Authorization Profile is Deny Access.  So it must not be associating my account with the group with the Permit Access and using the Default Permissions.So it does match the correct Access Service, and Identity Store.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Secondary ACS 5.1 Fails To Deregister After IP Change On Primary

Aug 9, 2011

IP address of Primary had to be changed, to respond to a hardware failure of TACACS server with IP in many device configs.
 
Now the Secondary fails to respond to repeated "Deregister from Primary" requests, even after reload  - apparently because it cannot reach the Primary at its old IP address. 
 
Requesting Deregister in GUI generates pop-up that says,  "This operation will deregister this ACS Instance from the Primary Instance. Management applications on this ACS instance will be restarted and you will be required to login again.  After performing this operation

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Fails To Send Files To Sftp Server After Installing Patch 5

Jul 21, 2011

After we have installed patch 5 on several ACS 5.2 server they aren't able anymore to write their backups to the sftp servers. I tried to search on the bug tool kit, but it seems to be broken when searching for the keyword "sftp". It's the same when I try to do a "copy logs" with sftp as destination.running a debug I can see,

acs/admin# copy logs sftp://10.1.115.11/,Collecting logs...,Username: backupuser,Password: ,6 [16376]: transfer: cars_xfer.c[301] [admin]: sftp copy out of /var/tmp/ADElogs.tar.gz requested,6 [16376]: transfer: cars_xfer_util.c[412] [admin]: resolved server to 10.1.115.11,7 [16383]: transfer: sftp_copy.c[75] [daemon]: Executing SFTP command: /usr/bin/scp -o StrictHostKeyChecking=no /var/tmp/ADElogs.tabackupuser@10.1.115.11://ADElogs.tar.gz,% Error: Transfer failed3 [16376]: transfer: sftp_copy.c[230] [admin]: sftp_copy ERROR: command execution failed,3 [16376]: copy: cm_copy.c[1226] [admin]: Logs archive transfer to url sftp://10.1.115.11/ failed retcode=-306,acs/admin#

View 21 Replies View Related

Cisco :: ASA 5510 SSL - VPN Getting Certificate Validation Failure

Oct 25, 2009

Tried configuring SSL VPN using Certificate authentication using a Microsoft CA server. Truspoint created and mapped to SSL VPN. While connecting the SSL VPN getting certificate validation failure. find the error screen shot attached

View 4 Replies View Related

All HTTPS Sites Failing Validation

Apr 1, 2011

I just put together a new computer. After putting it together I installed Windows 7 64-bit. My problem is that every "https" website I go to fails at its certificate validation. Every browser I use (Firefox 4, Chrome, IE9) warns me that the security certificate failed the validation. If I click "continue anyway" the browser shows a blank page. This happens for every https site. I have tried mail.live.com, mail.google.com, bankofamerica.com, etc. I can't even connect to windows update (which is really bad). The problem is limited to this computer. All my other computers (2 laptops with windows 7 32 bit) connect to websites using https just fine. My computer is freshly installed, but I scanned for spyware/viruses/trojans and came up empty.

View 1 Replies View Related

Cisco VPN :: 5510 - Certificate Validation Failure With AnyConnect Only On MAC

Apr 2, 2012

I have an anyconnect account set up using version 3.0.5080 and connecting to an ASA 5510 base 8.2(2)17. We are using certificates for authentication. If I try and use the account on a windows machine it all works fine.
 
However on a mac running Lion if I try and connect via a web browser or already have the anyconnect client loaded and try to connect I always get “certificate Validation Failure”. I double checked the certificate was correct and am sure that is correct as it is the same certificate on the Windows and the mac. After searching online I have also tried editing the anyconnect profile to so it is set “certificate store override”, and put the certificates and key in the “user/.cisco/certificates” and  “/opt/.cisco/certificates” folders.
 
After further testing, if I change the anyconnect connection profile to “authentication aaa” I can connect fine. Then if I disconnect, change it back to “authentication certificate” I can connect fine the first time, but all the following subsequent efforts I make fail. If I repeat this process this happens each time, I can connect the first time but after that it fails with the same “certificate Validation Failure” error message. When it connects this first time I checked and confirmed that it is definitely using the certificate. I have also tried using both authentication methods (“authentication aaa certificate”) and had the same problem.
 
This leads me to believe that my configuration is correct and it is some bug in the anyconnect client or the ASA image. I have had a look through bugs and read somewhere that there was a bug on earlier versions of 8.4, but nothing about 8.2.

View 1 Replies View Related

Cisco VPN :: ASA 8.4.5 - AnyConnect Web Install Getting Certificate Validation Failure

Mar 21, 2013

I have an ASA (8.4.5) configured with a connection profile that does AAA and Certificate authentication. Once I have the anyconnect 3.1 on a win Xp system, it works perfectly. When I do a web install, it goes through the normal download, log-in, re-download then says "Certificate Authentication Failure" If I change the profile to AAA only, it installs fine. I even get the error if I launch from the web after I have the client on the PC. Why this is not working?

View 3 Replies View Related

Cisco :: WLC 5508 / Guest User Session Validation Failed

May 31, 2012

I am running a guest wireless network on a Cisco 5508 WLC with 6.0.202.0 code. My syslog is filling up with the following error message:

WLC: *May 15 12:32:59.244: %AAA-3-VALIDATE_GUEST_SESSION_FAILED: file_db.c:3968 Guest user session validation failed for guest_user10. Index provided is out of range..
 
The user that is assigned to the guest_user10 account works fine and has no idea this error is occurring.
 
This error message is occuring exactly every 15 minutes 24x7.
 
I believe I have a rogue user who has setup a device to try and login to the guest network automatically, every 15 minutes with the guest_user10 credentials. I need to track this device down. I need a way to find either the MAC or IP address of the device that is causing this error message. I have tried turning on AAA debugging on the controller but I dont get anything more than the above error. I have also tried using WCS to look at the client history but it only show the normal activity.

View 3 Replies View Related

Cisco Switching/Routing :: GLC-T Error SFP Validation Failed On Nexus 5548

Oct 19, 2012

We inserted GLC-T modules and on Nexus 5548 they are showing SFP validation Failed  , as per Cisco doc GLC-T is support . Since we have 28 such modules and all after inserting showing same error. please see the below details. I also try configuring speed and inserting modules but no result ..let me know whether my GLC-T module is supported on Nexus 5548
 
INMUMFDS1SWCORE01# show module
Mod Ports  Module-Type                      Model                  Status
--- -----  -------------------------------- ---------------------- ------------
1    32     O2 32X10GE/Modular Supervisor    N5K-C5548P-SUP         active *
2    16     O2 16X10GE Ethernet Module       N55-M16P               ok
3    0      O2 Daughter Card with L3 ASIC    N55-D160L3             ok

[code]

View 6 Replies View Related

Cisco Wireless :: Error Message On WLC5508 - Validation Of STAT_PAYLOAD Failed

Oct 24, 2012

Upon checking the logs, I'm seeing a lot of these messages:

*emWeb: Oct 25 14:11:01.345: #LOG-3-Q_IND: spam_lrad.c:10136 Validation of STAT_PAYLOAD failed - AP  00:3a:98:09:4e:d0

Always the same MAC address, which I assume is a Cisco AP trying to join. The output interpreter/message decoder isn't much useful. 5508 Controller running ver 7.3.101.0.

View 11 Replies View Related

Netgear Router With 27015 Port - Steam Validation Rejected Error

Apr 27, 2012

I have Counterstrike Scource and am wanting to setup a deticated server. I have a netgear router with 27015 port open and my nat type is open, however it keeps on giving me the "steam validation rejected" error. BTW it works fine on LAN, just not online.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 2960 Unprotected Identity Pattern Not Working As Expected

Oct 28, 2012

I'm trying to test such 802.1x wired environment:windows xp sp3 as supplicant windows NPS as radius server 2960 as authenticator latest anyconnect (3.1.01065) + nam and standalone profile editor.I have a question: What is the difference between protected identity pattern and unprotected identity pattern (set in nam profile editor)? As I understand documentation PEAP-MSCHAPv2 is a tunneled method and it uses un- protected identity pattern to protect user's identity during phase 0. But if I use any fake identity here (anonymous, anonymous@[domain], etc) access is rejected (Access-Reject in switch debugs). I have to use exacly the same pattern in unprotected identity pattern as in protected identity pattern ([username] or [username]@[domain]) to gain access, regardless of authenticaton mode (same in machine only, user only authentication).

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Group Mapping With LDAP External Identity Store

May 18, 2011

I have a new Cisco Secure ACS 5.2 on a VM. We want to use it to for administrative access to our Cisco equipment  with TACACS+. I am trying to map user permissions to different groups of devices based on active directory group membership, however it is not working.
 
I am using an LDAP (configured for secure authentication) external identity store. On the directory organization tab, I have confirmed the accuracy of the subject and group search base and the test configuration button shows that it's finding > 100 users and >100 groups.
 
On the directory groups page I have entered the groups according to the required format. cn=groupname1,ou=groups,dc=abc,dc=com
 
I have a rule based result selection under group mapping. I have two rules in the format below.
 
Conditon
LDAP:Externalgroups groupname1
Result
Identitygroup1
 
I have the default group set to a identity group named other. My problem is, no matter what user attempts to authenticate, the Default rule is applied, and the user is put into the other identity group.This occurs when I log on as a groupname1 user, groupname2 user, or as user that is not a member of either of those groups. LDAP authentication works and the user is able to logon to the device.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Create Microsoft Active Directory (AD) Identity Store?

Jul 11, 2011

We are using ACS 5.2 and we are trying to create a Microsoft Active Directory (AD) Identity Store. We have a user to be used in the Active Directory creation General page and we would like to know how the test communication / ACS to AD communication takes place.
 
Our user is a predefined user in AD and has admin rights, but the password expires every 60 days. Will this affect the communication between AD and ACS 5.2 at everytime the entered user's password expires?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Host Internal Identity Store / Per Group Modification

Jan 24, 2012

I'm currently looking for a solution in order to restrict the modification of the host internal identity store (add or delete MAC host) per group. The default administrator roles does not include "per group restriction". Under the ACS I defined one group per department? My objective it to allow each department to access their ACS MAC database to add or delete MAC addresses as required.

How to restrict internal identity store per group?Do I need to create new roles? and how?I was not able to get an answer from the ACS ADMIN manual.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved