Yup, it was the TA profile that was not being pushed to the switch. The profiles were correctly configured but there was something that was not assigned to the "Global" scope, I think.
-------------------------------------------
Original Message:
Sent: May 29, 2026 08:21 PM
From: ariyap
Subject: Central NAC - problem with wired authentication
the switch command to check the TA cert is installed.

also checking the Radsec application identity.

I am not sure when the cert gets pushed but I think it should be when you configure central NAC server group in switch system profile or AAA Authentication profile.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------
Original Message:
Sent: May 29, 2026 08:05 AM
From: JaimeVS
Subject: Central NAC - problem with wired authentication
No, I cannot find that line. What should I do in Central to push that?
Original Message:
Sent: May 29, 2026 07:59 AM
From: willembargeman
Subject: Central NAC - problem with wired authentication
Looks all good. Please can you check if the TA profile is correctly pushed to the switch?
Config line starts with:
crypto pki ta-profile sys_central_nac
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
Original Message:
Sent: May 29, 2026 07:53 AM
From: JaimeVS
Subject: Central NAC - problem with wired authentication
I just did.
Original Message:
Sent: May 29, 2026 06:24 AM
From: willembargeman
Subject: Central NAC - problem with wired authentication
I think so. Please share the output of the command show crypto pki certificate device-identity via a DM
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
Original Message:
Sent: May 29, 2026 04:48 AM
From: JaimeVS
Subject: Central NAC - problem with wired authentication
In show events -r I'm seeing a lot of entries like this one:
2026-05-29T10:44:53.208866+02:00 6000 port-accessd[20937]: Event|7709|LOG_WARN|UMM|-|Certificate *.cloudguest.central.arubanetworks.com rejected due to verification failure (30)
Is there a problem there?
Original Message:
Sent: May 28, 2026 03:01 PM
From: willembargeman
Subject: Central NAC - problem with wired authentication
Is TCP port 2083 allowed on the network to the Central NAC servers?
Can you share the output of the command show events -r and show crypto pki certificate device-identity (maybe best in a DM)
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125