Hi,
I see video on youtube using TPM Certificate
EAP-TLS with TPM Certificate on Aruba AP Uplink 802.1X
Now I tested it with my own CA (Enterprise CA) by importing the Root CA into Clearpass Onboard, activating the EST Server and setting up the EST on the Mobility Controller, and the solution worked.



But for next step, I have tried creating a CA in Clearpass Onbaord using Registration Authority (RA) Mode in order to test having Clearpass contact the Root / Intermediate CA using SCEP. Clearpass was able to fetch the Root / Intermediate CA, but when I enabled the EST Server In RA Mode and set EST on Mobility Controller, it cannot connect between MC and Clearpass.


My question is if I want the AP to enroll certificate from Root / Intermediate CA via SCEP, can I do that?
Or enrolling a certificate for an AP in creating a CA on Clearpass Onboard can only be supported in Root CA and Imported CA mode, Registration Authority (RA) mode is not support ?