Just add the methods that you use, remove everything else. If you use EAP-TLS, remove everything else. If you use PEAP-MSCHAPv2 (deprecated), just add [EAP MSCHAPv2]. If you do both, just add those two. For sure don't put MAC Auth methods in EAP authentication services.
How did you configure the client? That is probably where the problem is...
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jul 20, 2023 05:46 AM
From: housegregory
Subject: NEW PHONES GIVING CA ERRORS
Yes the EAP Certificate is signed by a private CA. We manually added the certificate to the client phone but we still get EAP Errors in the below.
But we have configured the below methods and client is sending EAP as a method.
Original Message:
Sent: Jul 20, 2023 04:55 AM
From: Herman Robers
Subject: NEW PHONES GIVING CA ERRORS
An EAP certificate signed by a private CA (Company CA) should work fine, and is what I would recommend.
However in order for modern Android clients to trust that certificate, you would need to install the Company CA (that signed the EAP certificate) in your client before you can connect to the network, and you would need to trust that. Having an automation tool (mentioned in my previous response) would make that more user friendly, but to verify that is indeed the issue I would configure it manually first.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jul 20, 2023 04:36 AM
From: housegregory
Subject: NEW PHONES GIVING CA ERRORS
Hello,
Thank you for your answer, we have Radius/ EAP certificate that is signed with Company's Certificate Authority. It's local certificate with the same domain as Clearpass. For new clients that can not associate with Wireless which type of certififcate we need to use?
Original Message:
Sent: Jul 20, 2023 03:36 AM
From: Herman Robers
Subject: NEW PHONES GIVING CA ERRORS
fatal by client - unknown_ca is clear: Your client does not know/trust the root CA that signed the RADIUS/EAP certificate on ClearPass.
What type of RADIUS/EAP certificate have you deployed on ClearPass, as in signed by which CA?
How do you provision your phones for network access? Note that in older Android versions you could ignore the server certificate (which allowed attacks on user credentials), in more recent versions you can no longer ignore the server certifcate for better security. That has as a result that these devices would need more configuration, and tooling for that would be strongly recommended. Tooling could be ClearPass Onboard for non-managed devices, or a Mobile Device Management for managed devices.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jul 19, 2023 12:05 PM
From: housegregory
Subject: NEW PHONES GIVING CA ERRORS
Hello,
We have a working setup that all of my certificates are valid and my previous clients can authenticate without a problem in my Aruba Wireless Network. But when clients get new mobile phone it's giving an error in the attachments. I don't know what changed in the client side in brand new phones. Any ideas?