Link to home
Start Free TrialLog in
Avatar of amigan_99
amigan_99Flag for United States of America

asked on

Is current WLC 5500 Device Certificate required for EAP-TLS to work?

In the document below I see that WLC device certificate be installed on the Cisco WLC as part of the overall getting EAP working process. If the device certificate expires - what would be the impact of any configured EAP-TLS? PEAP? It seems like I've read elsewhere that the certificates that mattered for EAP-TLS were on the wireless client and at the RADIUS server.

You can view the device certificate via WLC GUI at Security/IPSec Certs/ID Certs.

http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/100590-ldap-eapfast-config.html
ASKER CERTIFIED SOLUTION
Avatar of Craig Beck
Craig Beck
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of amigan_99

ASKER

That explains exactly what I saw among a group of WLC's - some with expired certs and some not. And it turns out the ones with good certs were doing EAP-TLS but with local EAP. Thank you very much for clarifying this!