Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

EAP-TLS on polycom phone

This thread has been viewed 6 times
  • 1.  EAP-TLS on polycom phone

    Posted Feb 11, 2020 02:02 PM

    Hello,

     

    I'm in the middle of testing a deployment of dot1x. It works fine for my windows clients, but when I tried to authenticate a polycom phone, I was getting the following message:

     

    EAP-TLS: fatal alert by client - unknown_ca
    TLS Handshake failed in SSL_read with error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca
    eap-tls: Error in establishing TLS session

     

     

    I confirmed that the certificate it has is trusted by the CA. I the thumbprint and serial number match and I can see it's trusted when I import the cert anywhere else. Any suggestions on where to check into this? 



  • 2.  RE: EAP-TLS on polycom phone

    EMPLOYEE
    Posted Feb 11, 2020 02:07 PM

    [Correction]

     

    looks like the client (Polycom) is not trusting the server cert, is the server cert signed by public CA? if not, it should be public and something that Polycom trusts, or you need to remove server cert validation, in the 802.1x configuration.

     

     

    -

     



  • 3.  RE: EAP-TLS on polycom phone

    Posted Feb 11, 2020 02:23 PM

    It should trust the CA. I installed it via SCEP (MSCEP/NDES) and I can see that it has the CA cert installed and it recognizes the certificate as a signed CA cert. 

     

    Furthermore the ADCS lists it as trusted in it's chain. Is it not transmitting it? 



  • 4.  RE: EAP-TLS on polycom phone

    EMPLOYEE
    Posted Feb 11, 2020 02:40 PM

    A Pcap from Clearpass, while the authentication is happening would help to see if the transmission is failing or not trusting.

     

    --

     



  • 5.  RE: EAP-TLS on polycom phone

    Posted Feb 11, 2020 03:04 PM

    It's definitely sending the certificate. I am getting logs on the CPPM side and I can see radius requests coming in on the PCAP. 



  • 6.  RE: EAP-TLS on polycom phone

    Posted Feb 11, 2020 03:07 PM
    Did you import the RootCA in the ClearPass trust list?



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 7.  RE: EAP-TLS on polycom phone

    Posted Feb 11, 2020 03:08 PM

    Yes I did. I am using this CA already for EAP-TLS in my wireless solution with no issues. 



  • 8.  RE: EAP-TLS on polycom phone

    EMPLOYEE
    Posted Feb 11, 2020 04:44 PM

    could you please share the capture, something is missing, here.

     

     

    --

     



  • 9.  RE: EAP-TLS on polycom phone
    Best Answer

    EMPLOYEE
    Posted Feb 12, 2020 03:59 AM

    The message: "fatal alert by client - unknown_ca" is 100% clear: the client does not trust the root CA for the RADIUS EAP Certificate that is presented.

     

    Such an issue has to be solved in the client. I would double-check the phone configuration, and verify that ClearPass is actually using the certificate signed by the CA that is trusted by the phone. You may be lucky and get additional logs/info in the phone; but at the moment the phone is not trusting the cert that is sent by ClearPass.