Security

 View Only
last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

EAP-TLS with Windows not working with SCEP Certificates

This thread has been viewed 2 times
  • 1.  EAP-TLS with Windows not working with SCEP Certificates

    Posted 5 hours ago

    Hey guys,

    So I am testing a new deployment option with an Azure based CPPM with Onboard + Intunes SCEP extension. The solution has successfully deployed client certificates to my windows devices. 

    I am manually configuring the WiFi and I have not been able to get the devices to authenticate. In theory EAP-TLS I do not need an authentication source as I only want to trust the certificate. Next step will be adding Entra account validation, but still stuck on the basic authentication step.

    Authentication fails with the following error:

    EAP-TLS: fatal alert by server - unknown_ca
    TLS Handshake failed in SSL_read with error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed
    eap-tls: Error in establishing TLS session

    The client is selecting the right cert, which was created by the Onboard CA and it also has the root cert as a Trusted CA.

    The Onboard CA ROOT cert is in the CPPM trust list and set the EAP and Others for the usage. I cannot figure out why it is reporting "unknown_ca".  I have tried disabling "verify the server identity" on the client side, but that didn't change anything

    Service is using EAP-TLS authentication method with authorization disabled. CPPM is on version 6.12.2. Client does have a TPM chip, but the error seems unrelated.

    Any ideas?

    Thanks,

    RK



  • 2.  RE: EAP-TLS with Windows not working with SCEP Certificates

    Posted 4 hours ago

    Nevermind, found my mistake. Will publish results in a bit.

    vs.