<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: PEAP failed SSL/TLS handshake because the client rejected the radius server certificate in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57690#M4259</link>
    <description>Tx Andrew.&lt;BR /&gt;
&lt;BR /&gt;
It is the accesspoint itself being a radiusclient in our setup . We are configuring 802.1x on the wired network. Also AP's themselves need to be authenticated. Therefore we have configured AP's Ge1 interface as dot1xsupplicant (username/pass). I installed CA certificate chain on AP as trustpoint. &lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Sun, 15 Oct 2017 19:47:00 GMT</pubDate>
    <dc:creator>Jan_van_de_Bor</dc:creator>
    <dc:date>2017-10-15T19:47:00Z</dc:date>
    <item>
      <title>PEAP failed SSL/TLS handshake because the client rejected the radius server certificate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57688#M4257</link>
      <description>Extreme ap6532 (wing 5.8) Ge1 interface configured as dot1xsupplicant (client) for wired 802.1x authentication of AccessPoint connected to cisco 2960x switch (15.2(4)E5) configured with cisco ISE 2.3 as radiusserver. During authentication of AP a radius server message "PEAP failed SSL/TLS handshake because the client rejected the radius server certificate.&lt;BR /&gt;
&lt;BR /&gt;
Configured CA certificate chain (same as on radius server, as trustpoint on AP, but still problem exists.&lt;BR /&gt;
&lt;BR /&gt;
Somebody experience with Extreme AP Wing 5.x configured as dot1xsupplicant ?&lt;BR /&gt;
&lt;BR /&gt;
Please help. Thanks.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sun, 15 Oct 2017 19:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57688#M4257</guid>
      <dc:creator>Jan_van_de_Bor</dc:creator>
      <dc:date>2017-10-15T19:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: PEAP failed SSL/TLS handshake because the client rejected the radius server certificate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57689#M4258</link>
      <description>The client MUST trust the CA certificate that issued the Radius server's certificate.  Make sure that it is in the client's Trusted root CA list.</description>
      <pubDate>Sun, 15 Oct 2017 19:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57689#M4258</guid>
      <dc:creator>Andrew_Webster</dc:creator>
      <dc:date>2017-10-15T19:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: PEAP failed SSL/TLS handshake because the client rejected the radius server certificate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57690#M4259</link>
      <description>Tx Andrew.&lt;BR /&gt;
&lt;BR /&gt;
It is the accesspoint itself being a radiusclient in our setup . We are configuring 802.1x on the wired network. Also AP's themselves need to be authenticated. Therefore we have configured AP's Ge1 interface as dot1xsupplicant (username/pass). I installed CA certificate chain on AP as trustpoint. &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sun, 15 Oct 2017 19:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57690#M4259</guid>
      <dc:creator>Jan_van_de_Bor</dc:creator>
      <dc:date>2017-10-15T19:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: PEAP failed SSL/TLS handshake because the client rejected the radius server certificate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57691#M4260</link>
      <description>Can you copy the port config you have done?</description>
      <pubDate>Mon, 16 Oct 2017 11:56:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57691#M4260</guid>
      <dc:creator>Timo1</dc:creator>
      <dc:date>2017-10-16T11:56:00Z</dc:date>
    </item>
    <item>
      <title>RE: PEAP failed SSL/TLS handshake because the client rejected the radius server certificate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57692#M4261</link>
      <description>Accesspoint AP6532 (AP6532 version 5.8.6.0-011R)&lt;BR /&gt;
&lt;BR /&gt;
profile ap6532 default-ap6532&lt;BR /&gt;
.....&lt;BR /&gt;
....&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  dot1x supplicant username zebra-ap password *xyz*&lt;BR /&gt;
&lt;BR /&gt;
tx Timo.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 16 Oct 2017 12:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57692#M4261</guid>
      <dc:creator>Jan_van_de_Bor</dc:creator>
      <dc:date>2017-10-16T12:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: PEAP failed SSL/TLS handshake because the client rejected the radius server certificate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57693#M4262</link>
      <description>Problem solved. It seemed ISE was forcing EAP/TLS where AP was expecting EAP/MD5. Therefore responding "Bad certificate (42)"&lt;BR /&gt;
&lt;BR /&gt;
Also in radius log found: sslv3 alert bad certificate:s3_pkt.c:1493:SSL alert number 42&lt;BR /&gt;
&lt;BR /&gt;
This error message tells: the server demands you authenticate with a certificate, and you did not do so.&lt;BR /&gt;
&lt;BR /&gt;
Changed authentication rule on ISE to allow/ask EAP/MD5, now AP configured as dot1xsupplicant authentication successfull !&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 16 Oct 2017 17:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/peap-failed-ssl-tls-handshake-because-the-client-rejected-the/m-p/57693#M4262</guid>
      <dc:creator>Jan_van_de_Bor</dc:creator>
      <dc:date>2017-10-16T17:58:00Z</dc:date>
    </item>
  </channel>
</rss>

