howartp Posted March 10, 2020 Posted March 10, 2020 Good morning. We use UniFi with NPS to provide Radius auth. When a user connects their iPad to the wifi, the cert they're prompted with has an expiry of 7th March 2020 (ie yesterday) and is the local self-signed certificate from the NPS server. However, in NPS > Policies > Constraints > PEAP > the certificate there is NOT the one that is expired. (It's our realworld cert that expires on 12th March and is already renewed to 2021) If I set UniFi not to use NPS, it doesn't prompt the cert error, so i'm presuming it's definitely NPS. I have changed the UniFi keystore cert pair already, but that also uses our realworld cert so wouldn't be prompting 7th March. I've restarted UniFi controller and the NPS server fully. Can anyone suggest where else I would find a certificate setting that I need to update for UniFi/NPS not to prompt an expired cert? Peter
Duke5A Posted March 10, 2020 Posted March 10, 2020 The cert we use on our NPS instance is specified in two different places: Network Policy Server > Policies > Connection Request Policies > (Policy Name) > Settings Tab > Authentication Methods > EAP Type: PEAP <-- Edit Network Policy Server > Policies > Network Policies > (Policy Name) Settings > Constraints Tab > Authentication Methods > EAP Type: PEAP <-- Edit
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now