ITGuyNW Posted August 23, 2024 Posted August 23, 2024 Hi all Bit of an odd one. Moved over to certificate based authentication for radius on Windows Server. Brand new/recent/new-ish imaged laptops pick up the cert/gpo update fine and connect to Wi-Fi. These machines are getting the cert through a PDQ package as there's a Microsoft article saying sending the cert out via GPO is broke? Anyway Long standing laptops are struggling, mostly with "Reason Code: 295 Reason: A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider." Now I've been through the affected laptops, checked certs, checked NTauth and they have the same certs as the other laptops that connect fine. Anyone else know whether there's another cache or check that can be made to get these laptops to connect? I feel like I'm missing something obvious. Any one seen this or can help? Thanks
psydii Posted August 23, 2024 Posted August 23, 2024 Hi all Bit of an odd one. Moved over to certificate based authentication for radius on Windows Server. Brand new/recent/new-ish imaged laptops pick up the cert/gpo update fine and connect to Wi-Fi. These machines are getting the cert through a PDQ package as there's a Microsoft article saying sending the cert out via GPO is broke? Anyway Long standing laptops are struggling, mostly with "Reason Code: 295Reason: A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider." Now I've been through the affected laptops, checked certs, checked NTauth and they have the same certs as the other laptops that connect fine. Anyone else know whether there's another cache or check that can be made to get these laptops to connect? I feel like I'm missing something obvious. Any one seen this or can help? Thanks Do they definitely trust the root ca?
Davit2005 Posted August 23, 2024 Posted August 23, 2024 Was the new cert pushed out before the old cert ran out?
ITGuyNW Posted August 29, 2024 Author Posted August 29, 2024 Yeah the certificates are definitely in the root trust and had them before the old one ran out. I've back to PEAP using the same cert and it all works fine. I've also noticed that there's no issue with this on Windows 11 but Windows 10 only gives this error. Just going to stick to PEAP for now and move to cert when I move everyone to Windows 11 over the next few months.
mullet_man Posted September 15, 2025 Posted September 15, 2025 (edited) On 23/08/2024 at 10:52, ITGuyNW said: Hi all Bit of an odd one. Moved over to certificate based authentication for radius on Windows Server. Brand new/recent/new-ish imaged laptops pick up the cert/gpo update fine and connect to Wi-Fi. These machines are getting the cert through a PDQ package as there's a Microsoft article saying sending the cert out via GPO is broke? Anyway Long standing laptops are struggling, mostly with "Reason Code: 295 Reason: A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider." Now I've been through the affected laptops, checked certs, checked NTauth and they have the same certs as the other laptops that connect fine. Anyone else know whether there's another cache or check that can be made to get these laptops to connect? I feel like I'm missing something obvious. Any one seen this or can help? Thanks Hi @ITGuyNW did you ever get to the bottom this? Am experiencing the error "A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider." on our DCs but it seems that the clients are still connecting. Am really not well up on certificates, the workstation certificate expired and was renewed earlier in the year so I thought all was good but I know Microsoft are hardening certificates in next months patches so I think I need to get this sorted or we could be without wireless soon which would be a little bit of an inconvenience. Edited September 15, 2025 by mullet_man
psydii Posted September 16, 2025 Posted September 16, 2025 17 hours ago, mullet_man said: or we could be without wireless soon which would be a little bit of an inconvenience. ....and the understatement of the year award goes to... 1 1
ITGuyNW Posted September 16, 2025 Author Posted September 16, 2025 If I remember correctly, I ended up blowing the whole thing up from orbit and redoing it all, which meant plugging every ones laptop in to get the cert. Everything looked the same but I still feel like it was a stuck cert or something stopping everything working. 1
mullet_man Posted September 16, 2025 Posted September 16, 2025 1 hour ago, psydii said: ....and the understatement of the year award goes to... Haha - well I think with the thanks of a friend worked out the issue (I hope)
mullet_man Posted September 16, 2025 Posted September 16, 2025 23 minutes ago, ITGuyNW said: If I remember correctly, I ended up blowing the whole thing up from orbit and redoing it all, which meant plugging every ones laptop in to get the cert. Everything looked the same but I still feel like it was a stuck cert or something stopping everything working. Ouch! Although I had to do that earlier in the year, when ours expired. The issue is fixed with this reg key - applying this key and rebooting the DCs seems to have cleared the errors in the event log. Windows Server: Issues with Windows Hello issue and Kerberos events caused by April 2025 updates confirmed | Born's Tech and Windows World My worry was the article that suggests error ID 21 is related to the certificate hardening MS are doing. Protections for CVE-2025-26647 (Kerberos Authentication) - Microsoft Support Mild panic maybe averted!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now