Is it possible to configure Pulse on an iOS device to only use Client Cert authentication or do you need AD or RSA secondary authentication? The goal is an Ôalways on vpnÕ without users having to enter a username from mobile devices. I have done the following: - Created a Certificate Authentication server on the IVE 7.3R1 - Configured Realm/Role Mapping - Imported Certs on IVE: Device, Trusted Client, Trusted Server CAÕs - Imported Certs on iPAD via email and imported w/ iphone config utility for Root CA, Intermediate CA & Client CA - Installed Pulse on iPAD iOS 6.0.1, Pulse 4.1.0 w/ cert Seeing the following errors: Event Log (points to a Windows error in the kbaÕs) SSL negotiation failed while client at source IP x.x.x.x' was trying to connect to x.x.x.x'. Reason: 'decryption failed or bad record mac' Policy Trace (key usage on cert is Digital Signature, Non-Repudiation) Client certificate validation failed: FAILED: 26 unsupported certificate purpose
... View more