Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

EAP-TLS: fatal alert by client - unknown_ca

This thread has been viewed 55 times
  • 1.  EAP-TLS: fatal alert by client - unknown_ca

    Posted Sep 06, 2017 05:57 AM
    Hi, I installed new clearpass, last release, I restored backup and I added new certificates (I have internal ROOT CA - this is in trusted list). All laptop work fine but all mobile devices give me error "EAP-TLS: fatal alert by client - unknown_ca". I try to use self-signed certificate but not run nothing. Tablet and smartphone have old certificate from old ROOT CA, I must re-run onboard process on all devices or there is a simple way to accept mobiles? Thanks.


  • 2.  RE: EAP-TLS: fatal alert by client - unknown_ca

    EMPLOYEE
    Posted Sep 06, 2017 06:55 AM
    What are you using for the EAP server certificate?


  • 3.  RE: EAP-TLS: fatal alert by client - unknown_ca

    Posted Sep 06, 2017 08:37 AM
    Yes, AP105 e 205 with RADIUS clearpass


  • 4.  RE: EAP-TLS: fatal alert by client - unknown_ca

    EMPLOYEE
    Posted Sep 06, 2017 08:38 AM

    Please tell us about your EAP server certificate. Is it public CA-signed, self-signed or internally signed? Are your devices managed or unmanaged?



  • 5.  RE: EAP-TLS: fatal alert by client - unknown_ca

    Posted Sep 06, 2017 08:40 AM
    Internal CA with devices managed


  • 6.  RE: EAP-TLS: fatal alert by client - unknown_ca

    EMPLOYEE
    Posted Sep 06, 2017 08:44 AM
    The device doesn’t appear to have the signing CA of the EAP server certificate installed in it’s trust store.


  • 7.  RE: EAP-TLS: fatal alert by client - unknown_ca

    Posted Sep 06, 2017 09:18 AM
    I load RADIUS certificate of my internal CA on trusted store of clearpass. Onboarded certificates are generated by OLD_CA while now I have a RADIUS certificate from NEW_CA. Both _CA are on trusted list of clearpass.


  • 8.  RE: EAP-TLS: fatal alert by client - unknown_ca

    EMPLOYEE
    Posted Sep 06, 2017 09:25 AM
    The signing CA of the EAP server certificate needs to be installed on the clients and configured in the supplicant.


  • 9.  RE: EAP-TLS: fatal alert by client - unknown_ca

    Posted Sep 07, 2017 04:48 AM
    I solved with restore of old certificates, but this expire next year. Can I push new certificate automatically on all mobile devices with onboard system? PS I have a new root CA.