03-04-2014 07:25 AM - edited 07-05-2021 12:20 AM
Hi All,
I'm aware of that in eap-tls, the server-side cert will be pushed to the wireless client. I'm wondering if the CA root cert of the Radius server will be pushed as well. If not, I guess the client must have the CA cert pre-installed. Is there any documentation to describe this?
Thanks in advance.
Robert
Solved! Go to Solution.
03-04-2014 07:35 AM
EAP-TLS requires that the client and radius trust the root CA. The radius will not push down the root CA cert and that needs to be installed on the device. If these were all domain computer's then the root CA would be pushed. If not, then you have to setup your CA to be able to issue certs to non domain machines
Sent from Cisco Technical Support iPhone App
03-04-2014 07:35 AM
EAP-TLS requires that the client and radius trust the root CA. The radius will not push down the root CA cert and that needs to be installed on the device. If these were all domain computer's then the root CA would be pushed. If not, then you have to setup your CA to be able to issue certs to non domain machines
Sent from Cisco Technical Support iPhone App
03-04-2014 07:57 AM
Thanks Scott.
I'm a little bit confused. Based on the following url, somebody said sever will send the server cert and the CA. Can you show me the documentation that can explain in detail.
When the server sends a certificate, it actually sends a certificate chain, including the CA which issued it, and the CA above it, and so on, up to the root (the root itself may be sent, but this is optional).
03-04-2014 08:05 AM
Root CA is not sent when doing EAP-TLS... the radius sends its certificate to the client and the client has to trust the root CA.... search Goolge for: eap-tls non-domain machines
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide