Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass EAP-TLS Timeout _ Error code 9002 _ Client did not complete EAP Transaction

This thread has been viewed 63 times
  • 1.  Clearpass EAP-TLS Timeout _ Error code 9002 _ Client did not complete EAP Transaction

    Posted May 16, 2019 09:14 AM

    Hi Guys,

     

    I installed ClearPass recently in my office and I am experimenting with 802.1x authentication.

    I am able to authenticate Users using EAP-TLS

    but I am not able to auth MACHINES using EAP-TLS.

     

    The machines and the ROOT-CA are in the same domain.

    I configured my ClearPass as a SubordinateCA.

     

    I am not 100% if I am doing it right.

     

    The machine TRUSTS the ROOT-CA and the radius.cert from the ClearPass.

     

    From the machine itself I entered CertSrv and asked for a 'Computer' (templete) certificate, downloaded and installed it on both 'user' and 'local machine' under "Personal" folder.

     

    User auth - works great !

    Machine auth - not working with error 9002.

     

    I would really appriciate any help.

     

     

    Regards,

    Omri

     

    Edit:

    Forgot to add:

    I manually configured the Wireless adapter for EAP-TLS and I unchecked "verify the servers' identity".



  • 2.  RE: Clearpass EAP-TLS Timeout _ Error code 9002 _ Client did not complete EAP Transaction

    Posted May 17, 2019 11:57 AM

    You should ALWAYS validate the server. Otherwise, why use RADIUS, especially EAP-TLS, at all?

     

    The only time I've seen the timeout error (unable to complete transaction) is when the trust relationship with the computer and AD had been broken.

     

    A simple test would be to rejoin the computer to the domain.



  • 3.  RE: Clearpass EAP-TLS Timeout _ Error code 9002 _ Client did not complete EAP Transaction

    Posted May 17, 2019 12:53 PM
    Is this for wired or wireless?

    Sent from Mail for Windows 10


  • 4.  RE: Clearpass EAP-TLS Timeout _ Error code 9002 _ Client did not complete EAP Transaction

    Posted May 17, 2019 01:57 PM
    With eap-tls there is no need to join clearpass in the domain.

    In most causes with this error (9002) the client is not correctly configured. You have already disabled validation so that is not an issue. Maybe the client can’t use the certificate you installed. Have you checked the event logs at the client?