802.1x Authentication fails while CHAP authentication succeeds
This document (7001667) is provided subject to the disclaimer at the end of this document.
Environment
Situation
rlm_eap_tls: <<< TLS 1.0 Alert [length 0002], fatal bad_certificate
Resolution
- Procure a third party SSL certificate that the workstations trust
- Reconfigure the workstation to not trust the SSL certificate by doing the following :
- Open the properties for the network connection on the workstation (e.g. "Wireless Network Connection Properties", "Wireless Networks", highlight the network desired, and then click on "Properties"). It should bring up a window that looks like:
- Click on the "Authentication" tab at the top.
- Click on the "Properties" button. It should bring up a window that looks like:
- Ensure that "Validate server certificate" is NOT checked.
- Open the properties for the network connection on the workstation (e.g. "Wireless Network Connection Properties", "Wireless Networks", highlight the network desired, and then click on "Properties"). It should bring up a window that looks like:
Additional Information
TLS Alert read:fatal:bad certificate
TLS_accept:failed in SSLv3 read client certificate A
rlm_eap_tls: SSL_read failed in a system call (-1), TLS session fails.
In SSL Handshake Phase
In SSL Accept mode
rlm_eap_tls: BIO_read failed in a system call (-1), TLS session fails.
eaptls_process returned 13
rlm_eap_peap: EAPTLS_HANDLED
rlm_eap: Freeing handler
modcall[authenticate]: module "eap" returns reject for request 19
Disclaimer
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7001667
- Creation Date: 16-Oct-2008
- Modified Date:03-Mar-2020
-
- SUSE Linux Enterprise Server
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com