Security

 View Only
last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

After clearpass certificate update timeouts with error code 9002 on ClearPass / Radius servers

This thread has been viewed 12 times
  • 1.  After clearpass certificate update timeouts with error code 9002 on ClearPass / Radius servers

    Posted 19 days ago

    Hello,

    After renewing the certificate for our SubCA

    I renewed the certificate of our two clearpass servers today and now my users have to confirm to continue the connection each time to connect to the SSID.

    And if they don't click on the SSID to connect, the users are simply not connected and in clearpass I can see them with a 9002 timeout error.

    I've tried with my computer with a new certificate issued by subCA and it's the same error.

    Would you have any idea how I can solve the problem and where this could be coming from? I've seen on other posts that changing the certificate on the clearpass server can cause this but I haven't found out how to fix it.

    Thank you for your help



  • 2.  RE: After clearpass certificate update timeouts with error code 9002 on ClearPass / Radius servers
    Best Answer

    Posted 19 days ago

    Hi

    This type of issue is very common with unmanaged clients and if you have managed clients, but the 802.1x profile on the client is slightly misconfigured.

    What type of clients are affected?

    You should investigate the 802.1x setting, if it's Windows computers managed by Active Directory you should check the GPO.

    Verify that your root ca certificate is selected as trusted in the GPO and that the checkbox for prompting users to confirm new certificates are unchecked.

    Also provide the names of rhe ClearPass Radius certifcate(s) in the connect to server(s) box.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 3.  RE: After clearpass certificate update timeouts with error code 9002 on ClearPass / Radius servers

    Posted 18 days ago

    Hello, 

    It's for windows 11 client and the SSID deployed by GPO

    Thank you for your reply. Yesterday I checked the ssid deployment configuration using GPO and it turns out that the radius server was not configured on the clearpass server ip. after changing this the problem is resolved. 

    Thanks for your help