Solved

Is current WLC 5500 Device Certificate required for EAP-TLS to work?

Posted on 2016-10-27
2
54 Views
Last Modified: 2016-10-27
In the document below I see that WLC device certificate be installed on the Cisco WLC as part of the overall getting EAP working process. If the device certificate expires - what would be the impact of any configured EAP-TLS? PEAP? It seems like I've read elsewhere that the certificates that mattered for EAP-TLS were on the wireless client and at the RADIUS server.

You can view the device certificate via WLC GUI at Security/IPSec Certs/ID Certs.

http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/100590-ldap-eapfast-config.html
0
Comment
Question by:amigan_99
2 Comments
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 41863320
You only need a certificate on the WLC if you're doing local EAP or web-auth.

To process EAP-style authentication with RADIUS it's not necessary to have a certificate on the WLC; only on the RADIUS server. Depending on the type of EAP authentication used you may also need a certificate on the client too.
1
 
LVL 1

Author Closing Comment

by:amigan_99
ID: 41863355
That explains exactly what I saw among a group of WLC's - some with expired certs and some not. And it turns out the ones with good certs were doing EAP-TLS but with local EAP. Thank you very much for clarifying this!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

DECT technology has become a popular standard for wireless voice communication. DECT devices are not likely to be affected by other electronic devices and signals because they operate in a separate frequency-band.
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now