Wireless Access

last person joined: 23 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Certificate mismatch between wireless controller and what is presented to my computer

This thread has been viewed 1 times
  • 1.  Certificate mismatch between wireless controller and what is presented to my computer

    Posted Jun 25, 2013 01:01 PM
      |   view attached

    Hi all,

     

    I am having an issue with my controller where I put the certificate of my NPS server in the AAA profile, and attempt to connect via PEAP to the wireless network. I go through the steps to connect and it tells me that the server can't be identified. I know this is incorrect because I took the server authentication certificate and put it on the default website in IIS and verified that I get no errors when browsing to the site. I viewed the thumbprint of the certificate I was being presented and it matched an older certificate that I was using that in fact wasn't signed. Have any of you seen this before?

     

    The only thought that I have is that the certificate being presented by the AAA profile isn't being presented at all, and it is going directly to a self-signed certificate by the local server... If this is the case, how can I fix that?

     

    Thanks in advance.



  • 2.  RE: Certificate mismatch between wireless controller and what is presented to my computer

    EMPLOYEE
    Posted Jun 25, 2013 01:12 PM

    Do you have termination enabled in the 802.1x authentication profile on the controller? This would use a cetificate installed on the controller.



  • 3.  RE: Certificate mismatch between wireless controller and what is presented to my computer

    Posted Jun 25, 2013 02:50 PM

    I didn't have it enabled. I switched it on and I still get an error that the server cannot be identifed. I did verify though, that the correct certificate thumbprint is coming through now.

     

    I went in to my certification authority and verified the certificate is still active and valid. Any ideas? I checked my PC's trusted root CA's and the ADCS server is in that list. Like I said, the certificate is valid when I browse to the local server through a web browser... Would it be smarter to figure out how to load that signed certificate directly on to the server, rather than terminating at the controller?

     

    Thanks for your help.



  • 4.  RE: Certificate mismatch between wireless controller and what is presented to my computer

    EMPLOYEE
    Posted Jun 25, 2013 03:20 PM

    You will always get the trust dialog on Windows, Mac and iOS if you have not configured the client to trust the CA for that connection. If the thumbprint matches, then that dialogue is expected. It is just saying that the certificate hasn't been explicity trusted for that SSID.

     

     



  • 5.  RE: Certificate mismatch between wireless controller and what is presented to my computer

    Posted Jun 25, 2013 03:23 PM

    Thanks for the resposne. Just to make sure I understand: I need to send out the connection info for this SSID via group policy or another method, and set this specific SSID to check against the internal CA, considering that the CA is already in the trusted certification authority store on my computer?



  • 6.  RE: Certificate mismatch between wireless controller and what is presented to my computer

    EMPLOYEE
    Posted Jun 25, 2013 03:29 PM

    Even if the device trusts the CA, the certificate trust is configured per connection (SSID). You can configure group policy to push out the 802.1x supplicant config that will trust your certificate for the network. See my post in the following thread:

     

    http://community.arubanetworks.com/t5/Authentication-and-Access/Windows-7-Windows-8-Wireless-error-Valid-Trust-Anchor/m-p/43570#M1118

     

     

    Tim

     

     



  • 7.  RE: Certificate mismatch between wireless controller and what is presented to my computer

    Posted Jun 25, 2013 03:36 PM

    Wow, thank you so much for your help. I just configured the GP, going to restart my PC and test.