Security

 View Only
Expand all | Collapse all

RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

This thread has been viewed 46 times
  • 1.  RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Sep 25, 2025 03:46 AM

    Hi,

    Anyone has experience in using EAP-TLS for Macbook Wi-Fi Connection?  We are using onboard CA as internal CA and pushing user and device certificate using Intune SCEP profiles.

    Root and Intermediate Cert also pushed from Intune MDM using Trusted Profiles. Root Cert linked with SCEP profiles for User/Device. Wi-Fi Profile also configured and pushed to the Device.

    Both user certificate and device certificate is showing this error when connected the SSID using EAP-TLS authentication and selecting the user or device cert.

    Any advice or recommendations would be greatly appreciated.



    -------------------------------------------


  • 2.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Sep 25, 2025 10:03 AM

    What are you doing for the RADIUS certificate on ClearPass and have you established the trust relationship for that RADIUS certificate CA on the client device?  Are you provisioning the Wi-Fi settings with Intune as well?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Sep 25, 2025 07:22 PM

    generally that error message indicates that the CA trust chain is not upload to ClearPass.

    you need to navigate to  Administration » Certificates » Trust List



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Sep 26, 2025 05:06 AM

    Just for your information, This setup works for Windows Machines. not for MacOS.  it is already in Trust list(Both Root and intermediate CA)

    -------------------------------------------



  • 5.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Sep 26, 2025 05:07 AM

    Yes. as we are using Clearpass Onboard CA for certificate authority it is automatically added to Trust List. Yes Wi-Fi Setting pushed from Intune Profiles.

    -------------------------------------------



  • 6.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Sep 27, 2025 02:07 AM

    I've got EAP-TLS working for Macbook using SCEP certificates and WiFi payloads pushed from other MDMs.

    Key things to check/configure:

    1. Root and Intermediate certificates trusted on the device
    2. WiFi configuration payload
      1. Security: Enterprise 
      2. Type: EAP-TLS
      3. ClearPass Onboard root certificate selected as the trust certificate 
      4. ClearPass server names listed  as the trusted certificate names

    Here's a couple of KB's that go into further details.

    https://learn.microsoft.com/en-us/intune/intune-service/configuration/wi-fi-settings-macos

    https://support.apple.com/en-au/guide/deployment/depabc994b84/web

    https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_(Windows%2C_macOS_and_iOS)

    -------------------------------------------



  • 7.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 03, 2025 02:21 AM

    Hi Tobi,

    Thanks for your response. I have managed to fix the issues by creating new radius server for CPPM. but now windows shows the certificate warning message when connecting SSID. 

    Could you please confirm whether a radius server certificate would shows the root certificate details when imported to CPPM.

    -------------------------------------------



  • 8.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 04, 2025 01:44 AM

    I've seen that in the following cases:

    • Certificate presented doesn't match the FQDN/IP.
    • Chain is not configured as a trusted certificate and/or server in the wireless profile.

    What I've done in the past is manually connect a device with the desired configuration (EAP-TLS or EAP-TEAP) and then export the config as an xml using the netsh wlan commands.

    Import Wi-Fi settings for Windows devices in Microsoft Intune - Microsoft Intune | Microsoft Learn

    You can then manually import the xml (using netsh wlan) on some test devices to confirm behaviour before importing the xml in Group Policy Management or used in an Intune profile.




  • 9.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 04, 2025 03:31 AM

    Your RADIUS server certificate, is it issued by the Onboard CA, or another CA?

    If the RADIUS server certificate is issued by another CA you must trust this certificate chain on the client side as well, and also configure the 802.1x WLAN profile to allow this CA chain to be utilized for the authentication, as mentioned by @tobi.coonan



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 10.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 04, 2025 04:15 AM

    Onboard CA.

    -------------------------------------------



  • 11.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 04, 2025 04:19 AM

    I believe we need to upload the root cert and intermediate cert and push to the devices from intune. and confiugre scep profile for user certificate. for EAP-TLS authentication need to push wi-fi profile and wired profile.

    do we need to upload the radius cert to the user devices?

    -------------------------------------------



  • 12.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 04, 2025 06:54 AM

    The clients need to trust the root and intermediate certificates. You don't need to upload the RADIUS server certificate to the clients.

    Can you provide information about your 802.1x profile configuration?



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 13.  RE: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session

    Posted Nov 04, 2025 09:23 PM
    netsh wlan show profiles Vick
     
    Profile Vick on interface Wi-Fi:
    =======================================================================
     
    Applied: All User Profile
     
    Profile information
    -------------------
        Version                : 1
        Type                   : Wireless LAN
        Name                   : Vick
        Control options        :
            Connection mode    : Connect automatically
            Network broadcast  : Connect even if this network is not broadcasting
            AutoSwitch         : Do not switch to other networks
            MAC Randomization  : Disabled
     
    Connectivity settings
    ---------------------
        Number of SSIDs        : 1
        SSID name              : "Vick"
        Network type           : Infrastructure
        Radio type             : [ Any Radio Type ]
        Vendor extension          : Not present
     
    Security settings
    -----------------
        Authentication         : WPA2-Enterprise
        Cipher                 : GCMP
        Authentication         : WPA2-Enterprise
        Cipher                 : CCMP
        Security key           : Absent
        802.1X                 : Enabled
        EAP type               : Microsoft: Smart Card or other certificate (EAP-TLS)
        802.1X auth credential : Machine or user credential
        Cache user information : Yes
     
    Cost settings
    -------------
        Cost                   : Unrestricted
        Congested              : No
        Approaching Data Limit : No
        Over Data Limit        : No
        Roaming                : No
        Cost Source            : User

    -------------------------------------------