Bosch Building Technologies

    cancel
    Showing results for 
    Search instead for 
    Did you mean: 

    Bosch IP cameras: authentication failed in RADIUS server due to unsupported certificate

    Possible causes and solution(s)

     

    Symptoms

     

    During the authentication process with Bosch cameras to a RADIUS server, the event “5400 Authentication failed” occurs.

    Even that the certificates were generated, uploaded to camera, uploaded to server, in the authentication process in the last step, this message is displayed.

    Central_Support_0-1702979558833.pngCentral_Support_1-1702979576573.png

     

    Solution

     

    To be able to make the dot1.x work with the certificate, you have to modify the Certificate:

    • the Enhanced Key Usage to only “Client Authentication”
    • and add a Subject Alternative Name: your EAP identity
      note: According to RFC5216 the EAP-TLS Identity must be identical to the 'subjectAltName' field in the certificate

    Then, the Bosch camera should authenticate via 802.1x

    Nice to know.png Nice to know:

     

    info.png If the above recommendation doesn’t solve the failure, please provide the Central Technical Support team with the following:

    • Wire-shark from port mirror where camera gets connected to
      • First start the capture before plugin the camera to the switch
    • Gather all used certificates + passwords if needed
    • Camera Config file (pull at time off other logs) + passwords for service and loading
    • Camera maintenance log
    • Network diagram
    • Configuration/settings + used certificates of authenticating server
    • Install on the Wireshark PC a syslog server and configure printouts: syslog_dbg; eapol; ssl; this way the syslog server starts automatically collecting when camera gets connected to the switch and is in sync with the matching WireShark
    • Are there other cameras that work with EAP-TLS? If yes, please let us know the model of the other camera that are working with these certificates.
    • a screenshot showing the client and server certificates and its usage that has been assigned. Similar with:
    Central_Support_2-1702979685078.png
    Version history
    Last update:
    ‎12-19-2023 10:57 AM
    Updated by:
    Labels (6)
    Contributors
    Icon--AD-black-48x48Icon--address-consumer-data-black-48x48Icon--appointment-black-48x48Icon--back-left-black-48x48Icon--calendar-black-48x48Icon--center-alignedIcon--Checkbox-checkIcon--clock-black-48x48Icon--close-black-48x48Icon--compare-black-48x48Icon--confirmation-black-48x48Icon--dealer-details-black-48x48Icon--delete-black-48x48Icon--delivery-black-48x48Icon--down-black-48x48Icon--download-black-48x48Ic-OverlayAlertIcon--externallink-black-48x48Icon-Filledforward-right_adjustedIcon--grid-view-black-48x48IC_gd_Check-Circle170821_Icons_Community170823_Bosch_Icons170823_Bosch_Icons170821_Icons_CommunityIC-logout170821_Icons_Community170825_Bosch_Icons170821_Icons_CommunityIC-shopping-cart2170821_Icons_CommunityIC-upIC_UserIcon--imageIcon--info-i-black-48x48Icon--left-alignedIcon--Less-minimize-black-48x48Icon-FilledIcon--List-Check-grennIcon--List-Check-blackIcon--List-Cross-blackIcon--list-view-mobile-black-48x48Icon--list-view-black-48x48Icon--More-Maximize-black-48x48Icon--my-product-black-48x48Icon--newsletter-black-48x48Icon--payment-black-48x48Icon--print-black-48x48Icon--promotion-black-48x48Icon--registration-black-48x48Icon--Reset-black-48x48Icon--right-alignedshare-circle1Icon--share-black-48x48Icon--shopping-bag-black-48x48Icon-shopping-cartIcon--start-play-black-48x48Icon--store-locator-black-48x48Ic-OverlayAlertIcon--summary-black-48x48tumblrIcon-FilledvineIc-OverlayAlertwhishlist