Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Getting EAP-PEAP FATAL ALERT on 6.11

This thread has been viewed 10 times
  • 1.  Getting EAP-PEAP FATAL ALERT on 6.11

    Posted 15 days ago

    Today we have migrated the clearpass from 6.10.8 to 6.11.7 and for a dot 1x service we are getting the error " 

    "RADIUS EAP-PEAP: fatal alert by client - unknown_ca
    eap-tls: Error in establishing TLS session "
    Same is working fine in 6.10.9
    Authorization source is local repository
    Is there any suggestion for the same 


  • 2.  RE: Getting EAP-PEAP FATAL ALERT on 6.11

    EMPLOYEE
    Posted 15 days ago

    Make sure you have all of the certificates loaded, enabled, and set to the proper usage. 



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Getting EAP-PEAP FATAL ALERT on 6.11

    Posted 15 days ago

    Yea I would say the same. as chuclher, since a restore doesn't install the certificates. Unknown_CA usually means that the certifiacte Clearpass is presenting isn't the one that the client trusts.



    ------------------------------
    John-Egil Solberg |
    ACMX#316 | ACCX#902
    ------------------------------



  • 4.  RE: Getting EAP-PEAP FATAL ALERT on 6.11

    Posted 14 days ago

    Yeah. It's in upgrade/migration instructions that you need to export certs before reimaging the machine and import certs back when completed.

    It would be much less hassle if backup could do it or if we have an option in Cert management to export/import our custom certs in bulk.

    For one or two certs it really doesn't matter, but still you can easily miss it when you are looking into trusted cert database.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2024
    ------------------------------