The test is in progress by generating an expired certificate and importing it to your PC.
Regarding eap-tls during ise setup
'Allow Authentication of expired certificates to allow certificate renewal in Authorization Policy'
There's a setting like this.
I understood that this setting allows authentication even if the client's certificate expires.
However, I imported the expired certificate and checked the setting, but it was not authenticated.
When you attempt to access the SSID,
'I can't connect because I need a certificate to log in. Contact your IT support representative.'
The phrase is displayed and there is nothing left in the live log of ISE.
I understood that this is not a failure to authenticate in ise, but that the expired certificate itself is judged by pc not to have a certificate.
If you test or actually use any place regarding the corresponding setting of ise, please share it.