Jump to content

Recommended Posts

Posted

Good morning.

 

We use UniFi with NPS to provide Radius auth.

 

When a user connects their iPad to the wifi, the cert they're prompted with has an expiry of 7th March 2020 (ie yesterday) and is the local self-signed certificate from the NPS server.

 

However, in NPS > Policies > Constraints > PEAP > the certificate there is NOT the one that is expired. (It's our realworld cert that expires on 12th March and is already renewed to 2021)

 

If I set UniFi not to use NPS, it doesn't prompt the cert error, so i'm presuming it's definitely NPS.

 

I have changed the UniFi keystore cert pair already, but that also uses our realworld cert so wouldn't be prompting 7th March.

 

I've restarted UniFi controller and the NPS server fully.

 

Can anyone suggest where else I would find a certificate setting that I need to update for UniFi/NPS not to prompt an expired cert?

 

Peter

Posted

The cert we use on our NPS instance is specified in two different places:

  1. Network Policy Server > Policies > Connection Request Policies > (Policy Name) > Settings Tab > Authentication Methods > EAP Type: PEAP <-- Edit
  2. Network Policy Server > Policies > Network Policies > (Policy Name) Settings > Constraints Tab > Authentication Methods > EAP Type: PEAP <-- Edit

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...