Avatar of YOlanie_Visser
YOlanie_Visser
Flag for Monaco asked on

CA Server Issue - CAS Crashed/RADIUS Errors

Hi Guys

I've run into a bit of an issue, my CA server crashed (No backup!)  a while back and I thought there wouldn't be any issues, but a few days back the certificate on the PDC expired and now any user trying to connect to the wireless is unable too, due to the RADIUS. It seems that because the certificate expired the RADIUS server has stopped working.

Any idea what the best solution is to get the wireless working again?
Setting up another CA?
Setting up a self signed certificate (using IIS) for the RADIUS?
If I do not setup another CA will there be any further consequences? All servers have been popping up auto enrollment certificate errors.

Any feedback will be great. Thanks!
Windows Server 2003

Avatar of undefined
Last Comment
Leon Fester

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Leon Fester

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
YOlanie_Visser

ASKER
dvt_localboy

I'm in the process of doing the cleanup, any idea how I will work around the RADIUS issue? Could I use a self signed cert just for the RADIUS? That would be the only reason why I would setup another CA,,,
Leon Fester

No a self signed certificate in the Radius server won't help you.
The simple reason: the Certificate Authority for that self signed certificate will not be found.

You also need to remember that the basis of PKI is that there is always an Authority that can verify a the validity of a certificate. Have a look at a valid certificate and check out the Certificate Path....it's needed for establishing if your Certificate is valid.
http://technet.microsoft.com/en-us/library/cc731853.aspx

Reasons for installing a CA
http://technet.microsoft.com/en-us/library/cc776679(v=ws.10).aspx

Additional reading that may interest you:
http://social.technet.microsoft.com/wiki/contents/articles/987.windows-pki-documentation-reference-and-library.aspx
http://technet.microsoft.com/en-us/library/cc772670(v=ws.10).aspx
http://www.trainsignal.com/blog/active-directory-certificate-services
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes