Network Error: Clean Access Server could not establish a secure connection to Clean Access Manager at XXXXXXXX. This could be due to one or more of the following reasons: 1) Clean Access Manager certificate has expired 2) Clean Access Manager certificate cannot be trusted or 3) Clean Access Manager cannot be reached. Please report this to your network administrator.
-The cam and cas are synchronized with the time
-There is comunication betwen cam and cas by ssh
-I can Control the cas by the cam
The problem is when the user try to connecto to the network.
Its important, that the cam and cas are with the same time, well max 5 minutes of diference.
the cam can ping the cas and cas to cam.
you have to control the cas by the cam
Now you have to enter to the cas and regenerate the ssl certificate (Administration>CCA Manager>SSL>Generate Temporaly Certificate) but with the ip of the cam, later you have to reboot the cas, and wait until the cas be online by ping.
Next, you have to enter to the cam and regenerate the ssl certificate with the ip of the cam at (SSL>Generate Temporaly Certificate), and reboot the cam.
when you finished this steps you going to lose the control of cas by the cam.
next, export the certificate from the cam to the cas with te private key. And when you import the the certificate of the cam to the cas you can control the cas again by the cam.
I verify that the time was right in the CAM and the CAS and all good up there
The NAC solution that I am implementing is in Failover. I have 2 CAS and 2 CAM.
For the CAM's I use this names camsrv1 and camsrv2. then generate a CSR in the camsrv1 with the name camsrv3.mycompany.com corresponding to virtual ip and it exported to camsrv2, Install the CA certificate of the company and everything works perfect.