netsh wlan show profiles Vick
Profile Vick on interface Wi-Fi:
=======================================================================
Applied: All User Profile
Profile information
-------------------
Version : 1
Type : Wireless LAN
Name : Vick
Control options :
Connection mode : Connect automatically
Network broadcast : Connect even if this network is not broadcasting
AutoSwitch : Do not switch to other networks
MAC Randomization : Disabled
Connectivity settings
---------------------
Number of SSIDs : 1
SSID name : "Vick"
Network type : Infrastructure
Radio type : [ Any Radio Type ]
Vendor extension : Not present
Security settings
-----------------
Authentication : WPA2-Enterprise
Cipher : GCMP
Authentication : WPA2-Enterprise
Cipher : CCMP
Security key : Absent
802.1X : Enabled
EAP type : Microsoft: Smart Card or other certificate (EAP-TLS)
802.1X auth credential : Machine or user credential
Cache user information : Yes
Cost settings
-------------
Cost : Unrestricted
Congested : No
Approaching Data Limit : No
Over Data Limit : No
Roaming : No
Cost Source : User
-------------------------------------------
Original Message:
Sent: Nov 04, 2025 06:53 AM
From: jonas.hammarback
Subject: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session
The clients need to trust the root and intermediate certificates. You don't need to upload the RADIUS server certificate to the clients.
Can you provide information about your 802.1x profile configuration?
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Nov 04, 2025 04:18 AM
From: Beemarajan Dakshinamoorthy
Subject: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session
I believe we need to upload the root cert and intermediate cert and push to the devices from intune. and confiugre scep profile for user certificate. for EAP-TLS authentication need to push wi-fi profile and wired profile.
do we need to upload the radius cert to the user devices?
Original Message:
Sent: Nov 04, 2025 03:31 AM
From: jonas.hammarback
Subject: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session
Your RADIUS server certificate, is it issued by the Onboard CA, or another CA?
If the RADIUS server certificate is issued by another CA you must trust this certificate chain on the client side as well, and also configure the 802.1x WLAN profile to allow this CA chain to be utilized for the authentication, as mentioned by @tobi.coonan
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
Original Message:
Sent: Nov 03, 2025 02:21 AM
From: Beemarajan Dakshinamoorthy
Subject: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session
Hi Tobi,
Thanks for your response. I have managed to fix the issues by creating new radius server for CPPM. but now windows shows the certificate warning message when connecting SSID.
Could you please confirm whether a radius server certificate would shows the root certificate details when imported to CPPM.
Original Message:
Sent: Sep 27, 2025 02:06 AM
From: tobi.coonan
Subject: RADIUS EAP-TLS: fatal alert by client - certificate_unknown eap-tls: Error in establishing TLS session
I've got EAP-TLS working for Macbook using SCEP certificates and WiFi payloads pushed from other MDMs.
Key things to check/configure:
- Root and Intermediate certificates trusted on the device
- WiFi configuration payload
- Security: Enterprise
- Type: EAP-TLS
- ClearPass Onboard root certificate selected as the trust certificate
- ClearPass server names listed as the trusted certificate names
Here's a couple of KB's that go into further details.
https://learn.microsoft.com/en-us/intune/intune-service/configuration/wi-fi-settings-macos

https://support.apple.com/en-au/guide/deployment/depabc994b84/web
https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_(Windows%2C_macOS_and_iOS)