Not use 5.4 ACS for TLS authentication with a certificate not in the string

Hi all

I have installed ACS 5.4 and several wireless environments.

EAP - TLS is used to authenticate users of our area (of self-signed cetificates)

Then use PEAP and need for a real external cert... (Signed by Terena)

The problem is that I can use a single certificate for authentication EAP on ACS, and I need them both to work.

I see only 2 options:

1 configure the TLS network to authenticate without going through the ACS cert in the string (use the real one)

2. set up somehow to use two certificates, one for each service.

Please help, im desperate.

Thank you!

Naor

You can't have several certificates of server/identity on ACS for EAP flavours. As a best practice, get the third-party certificate and check to associate the certificate with the EAP protocols that use SSL/TLS tunneling: EAP - TLS, PEAP and EAP-FAST.

~ BR
Jatin kone

* Does the rate of useful messages *.

Tags: Cisco Security

Similar Questions

  • Can I still use my PCI-4351 for readings of tc type t, even if the unit is out of tolerance in the +/-2 .5V range?

    Hello

    I use a PCI-4351 for readings of TC type T, and after receiving it back from calibration, the 2.5V range came out by - 0.00003 V.  The rest of the calibration is within the tolerance.  Please tell us if the 2.5V range is used for playback of the thermocouple type T with the accessory CB - 68 t.  From my understanding, I don't think that the 0.625V beach is used for measurements of TC, and they all calibration.

    Thank you for your help.

    Michael Carter

    Hi Michael,

    You're right that you'll only need the gamme.625 for this measure.

    I am very disappointed to hear that your device was not properly calibrated.  It was our calibration?  If it were, I can try to you allow to send to us or something like that to remedy this situation.

    If there is anything else I can do to help correct this problem please let me know.

  • QT_TR_NOOP() macro does not mark the string for the extraction of the .ts file

    Hello

    Because I want to put all the translatable texts in one place, I defined a separate category for that. The .h file similar to below:

    #ifndef TEXTCONSTANTS_H_
    #define TEXTCONSTANTS_H_
    
    #include "qobject.h"
    
    class TextConstants : public QObject {
        Q_OBJECT
    
    public:
        static const char *SWITCH_APP;
    };
    
    #endif /* TEXTCONSTANTS_H_ */
    

    And the .cpp file similar to below:

    #include "TextConstants.h"
    
    const char *TextConstants::SWITCH_APP = QT_TR_NOOP("Switch App");
    

    Note that in the file above, I use QT_TR_NOOP() macro to mark the string given for extraction of the .ts file. This is mentioned in the documentation at https://developer.blackberry.com/native/documentation/cascades/device_platform/internationalization/....

    I then called tr (TextConstants:WITCH_APP) in a different subclass of QObject. The problem is that the text "App switch" is not extracted from the .ts file, why? If I call tr() and skip the text "App Switch" like tr ("Switch App"), this text is extracted from the .ts file. Am I missing a few things to make it work? Thank you.

    PS. I use® for QNX Momentics® IDE for BlackBerry® 10 native SDK, Version: 10.1.0, Build id: v201303191709

    Hello.

    I think you have misunderstood my suggestion.  I was only suggesting that you call the function tr() in your statement of constant ithat you posted nstead of QT_TR_NOOP(), not in other parts of your code, to see if the compiler accepts it and the chain gets extracted correctly.

    If this does not work, I'll try to track down the code of the work for the purposes of comparison.

    Sorry if I wasn't clear before.

  • LgFilter Agent not exclude the strings

    I have a big problem with a logfilter agent, agent do not exclude a string, the goal is the following:

    I need tha the agent finds the string: GTM-E, but exclude the JTF-E-CLOSEFAIL chain, I have the following configuration:

    * Match list

    Correspondence: gravity JWGE-E error: criticism

    Exclusion list

    Correspondence: gravity error GTM-E-CLOSEFAIL: criticism

    The two strings have the same severity, but it continue fire alams, how second try I change the gravity on the Fatal exclusions list, but continue the problema, could you help me please.

    Thank you.

    David,

    With the help of Rick, we got it works.  Use

    . * GTM-E. *.

    for your match condition, and

    . * GTM-E-CLOSEFAIL. *.

    for your exclusion.  And it should work as you wish.

    I had already tried the '. '. * "s on the status of game, but it wasn't until Rick told me to add these on the match condition too that I succeeded in my tests."

    Jeff

  • ORA-26744: STREAMS capture process "STRING" does not support the "STRING".

    Hi all

    I set up the flow of the oracle to help noted "How to configure one-way replication of SCHEMA [ID 301431.1] level flow" at the level of the schema

    All changes translate perfectly and was running smooth, but today, all of a sudden I faced the error and the capture below is abandoned

    ORA-26744: capture FLOW process 'STREAM_CAPTURE' does not support the "AMSATMS_PAWS". "' B_SEARCH_PREFERENCE ' for the following reason:
    ORA-26783: unsupported data type column

    Some suggestions on the forum are to add a negative ruleset, please suggest me how can I add a set of rules negative and if it is added to the ruleset negative then how will contribute to reflect changes made to this table in the target database...?

    Please help me...

    Thank you

    I have no clue why she treats your XMLTYPE stored as a CLOB as a binary XMLTYPE. The doc, we read:

    http://download.Oracle.com/docs/CD/B28359_01/server.111/b28321/ap_restrictions.htm#BABGIFEA

    Unsupported Data Types for Capture Processes
    
    A capture process does not capture the results of DML changes to columns of the following data types:
    
        *       SecureFile CLOB, NCLOB, and BLOB
        *      BFILE
        *      ROWID
        *      User-defined types (including object types, REFs, varrays, and nested tables)
        *      XMLType stored object relationally or as binary XML                   <----------------------------
        *      The following Oracle-supplied types: Any types, URI types, spatial types, and media types
    
    A capture process raises an error if it tries to create a row LCR for a DML change to a column of
    an unsupported data type. When a capture process raises an error, it writes the LCR that caused
    the error into its trace file, raises an ORA-26744 error, and becomes disabled. 
    

    For your support

    NOTE: 556742.1 -extended data type of support (EDS) to a stream

    to exclude the table:

    NOTE: 239623.1 -how to exclude a Table of Capture of Schema and replication when you use level streams schema replication

    Sounds like a specific patch. You have not indicated what version of Oracle you are using.

  • Renew the certificate in Cisco ACS for PEAP authentication

    Hi, we installed in laptops wireless customer a certificate created by Cisco ACS to authenticate, but its about to expire.

    How can I do to renew the certificate whithout affecting users.

    (1) Yes, we can generate a new cert but install the latter.

    (2) install generated new cert on the client.

    (3) install the new cert in ACS.

    Good plan and will probably work.

    Kind regards

    ~ JG

    Note the useful messages

  • ACS for device authentication

    Hello

    I'm looking to install a NAC appliance in our office and currently have an ACS server that handles wireless authentication.

    I would like to know if the CSA is able to authenticate users on a local network with 802.1 x and detection device (such as MAC address and ID)?

    If I can do it how you define on a CBS?

    Thanks in advance

    Paul

    As mentioned, the ACS authenticate what you ask. But you must enter all a mac address then.

    The ISE profiling engine did this in real time depending on the behavior of devices.

  • Can I use old time capsule for storage only with a new airport extreme (standard want latest HQ)?

    I have a time Capsule elders (802.11n). I would like to know if I can still use this time Capsule only as a network storage device, if I decide to build my network with a new Airport Extreme (802.11ac). If I can do that, how would I set up the network to continue automatic backups with a router to update?

    To do what you want, the new AirPort Extreme 802.11ac would be installed as the "main" network router The time Capsule would be connected to the AirPort Extreme, using a wired Ethernet cable connection, and the time Capsule should be configured to run in bridge with the service Mode Wireless off.

    Any Mac you want to save in the time Capsule would need to have Time Machine preferences on each Mac adjusted to ensure that the time Capsule has been set as the target for backup.

    If you decide to add the AirPort Extreme, post back for more information at this time, if you need installation instructions step by step.

  • Cannot use external ps/2 for keyboard USB with my Satellite A100

    I have a Satellite A100-064 occasionally, I want to use a keyboard 'good '. I have a Microsoft keyboard with a ps/2 connection added a usb adapter, but when I plug it in nothing happens. I don't want this Microsoft keyboard only to work, I want to just use it when I have a lot of typing to do.

    Hello

    Have you tried to enable Legacy USB emulation in the Toshiba HWSetup?
    This tool can be found in the Control Panel, or you can access the assistance of Toshiba.

    But this is only a slight hope. I m not 100% sure if it helps or not.
    A friend of mine tried to also connect the PS/2 keyboard to the portable USB via PS / 2-> USB adapter.
    But it didn t work.

    Finally, he replaced the keyboard with another USB keyboard and it worked.

  • Using Flex Performance Profiler for profiling Flex with Java Applications

    Hello

    I intend to use the Flex Profiler to profile my request.
    I have developed a model of application using Flex MXML, ActionScript classes for events and Cairngorm, Java , Oracle database and Blazeds.

    Can I use Flex Performance Profiler to profile my request. ??

    I ask this question as I have ad read the threshold to Adobe site and my Application includes java methods

    "You can use the Profiler to profile ActionScript 3.0 applications.

    Can someone please tell me what this means? and I can use the Performnace Flex Profiler.

    Season me please.

    If you want to evaluate the response time when you call a service, you can use Charles Web Debugging Proxy as it is able to control the calls using the AMF protocol.

    If you want to monitor is the ActionScript objects from Java in the class that retrieves the result in the service, you can use the Flex Profiler.

  • ColdFusion scheduled task for HTML files with javascript ajax call to the web service

    I have a regular html file, which are generated dynamically (on access to it) for a few seconds (about 7 to 10 seconds) as tables, lines that are added through javascript after having treatment and this process takes about 7-10 seconds of said.

    Using settimeout(), after 15 seconds (to ensure that the content has been correctly filled), I use a web service (.cfc with function with intrusion via cfmail tag inside) through the ajax javascript call, which captures all the html content of the page and sends it to marked e-mail ID - which, during normal operations, works very well - which page is accessible in the browser web and left pending for desired time of 15-20 seconds.

    However, the same page when I programmed in CF admin (even with the time-out of 60 seconds), it never fires the e-mail part.

    Can I have some advice, where I am doing wrong!

    Hi, I mean the scheduled activity could be accomplished using CF native heavyweight instead of light and fast javascript codes codes. Not a big problem anyway.

  • I would like to deal with the psd files for pdf files with Photoshop 2015 CC of the lot

    Have Photoshop 2015 CC would like to process files psd to pdf files in batch bridge, can't get output module to work tried all bridge for bridge to get to work, he used.

    You could combine the batch script and a simple action to save to the PDF format. Open a file and create the action.

    Make a new series:

    Do new action:

    The action should be save. Now save your file to PDF and stop the action.

    Go to the bridge and select the files you want to convert, and then go to tools > Photoshop > batch. Set as the screenshot shows:

    Benjamin

  • L10: Using a simple click for extended desktop

    Hello

    I use a satellite L10 for presentations. Is it possible to implement the extended one-click Desktop (a! via .exe, .reg,... file, etc.)? (A quick access key would be nice too)

    The problem is that if I start the computer without the external monitor / projector connected etc it is the only screen (normal office) and I have to right click, look for the option right etc) I want one button on my desktop / taskbar. (or shortcut)

    Thank you
    JP

    Hello

    Bob is right. Please see page 5-2 92 user manual. You will find explanation how to use the FN key combinations (hotkeys).

    Good bye

  • I ' v use my Apple Watch for a week

    I use my Apple Watch for a week, today my support function in the application of the physical condition has stopped working, I tried to restart my phone and my watch but nothing. Anyone have any ideas?

    HI - try the following steps:

    On your iPhone in the app shows, go to: Watch My > General > wrist Detection - make sure it's open.

    On your iPhone, in the application of the watch, go to: Watch My > privacy > disable Motion & Fitness - Fitness track (or, if it is currently disabled).

    Restart both devices by turning the two first set, and then restart your iPhone before restarting your watch:

    -To switch off your iPhone: press and hold the sleep/wake button until the Red slider appears. slide it to turn off. To restart, press and hold the sleep/wake button.

    -To switch off your watch: press and hold the button side until you see the cursor off the power; slide it to turn off. To reactivate: press and hold the side button until you see the Apple logo.

    If you disabled followed fitness in step 2, now return to the configuration and turn it back on (another reboot of both devices may also help).

  • Very close to the dumping of Mozilla Thunderbird. The slow is simply not worth the hassle and support sucks.

    I have been using Mozilla Thunderbird for many years. It has always been a good system. Now, I get so when I hit delete, it takes a minute or two to delete the e-mail message. I tried to follow all the instructions on the help system and have turned off Mcafee whenever I try to read my mail.

    I'm not an expert in computers, but can generally follow directions well enough. The help of this system Mazilla fact dependent on questions of a group doesn't make any easier these problems. I see the same questions asked by many people without clear answers to why this is happening.

    Unfortunately, if this problem is not resolved soon, I'll have to drop Mozilla for another system...

    Bruce Cunha
    [email protected]

    Saying suck it support is not exactly being polite towards those which expect free aid. I prefer to think that you are just frustrated and the offensive remark was not intentional.

    It would be useful that you could provide some information about your situation, etc.

    You have McAfee and you say stop reading emails, do not turn off completely, just stop it analyzes e-mails. This will mean that you don't have to keep it work and stop.
    Here are the instructions to do this.

    Please provide the following information, so that it is possible to get an understanding of your situation and the installation program:

    • What operating system do you use?
    • What version of Thunderbird?
    • It's an IMAP or POP e-mail account, that has the problem?
    • If IMAP - is it a gmail account?
    • You have one or more e-mail accounts?
    • How frequently you compact your folders?
    • When did finally empty and compact your deleted folder?
    • You have several folders?
    re: the Inbox
    
    • This file used as an Inbox for mail entering with only a few mails is inside or used to store a load of emails?
    • Have you set up archiving Options to archive by month and keep the folder structure?
    • Do you have emails Archive more of for example: one month, two months?

    Please answer the queries above, if the forum includes your current situation.

Maybe you are looking for

  • Sounds of notifications could not be changed

    So I've recently upgraded to IOS 10 However my notification sound had not acted the same as previously. All of my iMessages, Whatsapps, and Snapchats about the noise rang like how I recorded it. All this while they were still set to "Note". However,

  • Upgrade Vista to Windows 7 keyboard filter question

    I really need help with this... I have upgraded vista to the full retail version of Windows 7. Compatibility check says updating keyboard filter. I could not find much info about it and assumed it would not be too affect many except extra work I prob

  • Can mogu skinuti Windows 7 Professional MSDN SP1 DVD only

    Can mogu skinuti Windows 7 Professional MSDN SP1 DVD only

  • Licensing ASA ssl

    We have an ASA 5520 with a ssl 100 users license. We need to increase this but 250 is excessive. Y at - it an option to add more than 50 licenses or should we go up to 250? Sent by Cisco Support technique iPhone App

  • Visual studio express 2012 - need to create the source code project existing

    Hello I generally use Visual Studio Express editions to browse existing source projects. After upgrading to the new edition of 2012 for developing Windows Desktop (on Windows 7), I'm not able to see this wizard. Please help me to configure existing p