Security

 View Only
  • 1.  Changing NPS to Clearpass

    Posted Jan 27, 2019 07:11 AM

    We're currently using NPS with EAP-PEAP and would like to switch to Clearpass. However all the Windows clients seem to be configured to check server certificates, but no CAs are selected. Can NPS somehow not send the server certificate as the wireless network works currently?

     

    Clearpass sends the certificate and when I tried with test SSID the clients complaint that the certificate is trusted but not on the trusted CA list for the WLAN. Clients can connect once they click Connect.

     

    We're planning to do switchover during maintenance window and I'm not sure all the clients would get new GPO settings instantly if we tried seding new settings with CA added as trusted one. Any idea how to do the migration without causing problems for the users?



  • 2.  RE: Changing NPS to Clearpass
    Best Answer

    Posted Jan 27, 2019 10:29 AM
    The server certificate is a required component of encapsulated EAP methods. To get up and running, simply export the EAP server certificate from NPS and import to all nodes in your ClearPass cluster.