Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


WPA2-Enterprise with RADIUS/Microsoft NPS and 3rd Party Certificates

Posted on 2016-11-03
Medium Priority
Last Modified: 2016-11-13
i All - I'm hoping you can help out with a frustrating issue I'm having.  I have 2 Unifi AC Pro's and 2 SSIDs.  One that will allow all domain joined machines to join and another for other devices, such as phones and tablets that staff will authenticate using using their domain usernames and passwords.
I've setup PEAP using NPS following some guides I found and I've installed a cert from GoDaddy on the NPS server.  Everything works and users can authenticate, however, all devices are being prompted with certificate warnings that you have to accept to connect.  The message is slightly different depending on the device.  Windows 7 states:
The credentials provided by the server could not be validated.  We recommend that you terminate the connection and contact your administrator with the inforamation provided in the details.  You may still connect but doing so exposes you to security risk by a possible rogue server.
This cert is from a public CA, so I'm guessing I missed a step or configured something incorrectly.  The CN on the certificate is wifi.mydomain.com even though the NPS servername is actually nps.mydomain.local.  Could that be the issue?  I just used IIS on the NPS server to generate the certificate request.  What did I miss?  I have non-domain joined devices connecting so I don't want to use my own private CA.
I see quite a bit of forums on this topic, but they are all a few years old.  I'm hoping someone can guide me in the right direction.
Question by:polaris101
  • 3
  • 2
LVL 44

Expert Comment

by:Adam Brown
ID: 41873108
What name are your wireless APs configured to use for accessing the RADIUS server? That should match what is on the certificate. So your AP configuration determines whether the certificate is valid or invalid. If you have your APs configured to use the IP of the NPS server or the internal domain name, the certificate will be invalid with a 3rd party certificate. You'd need to change the AP configuration so it uses wifi.mydomain.com and make sure they are set up to pull DNS from a server that has an A record for wifi.mydomain.com that points to NPS.

Author Comment

ID: 41873118
Well my AP's use the IP address to point to the RADIUS server...unfortunately, it only accepts IP's and doesn't allow DNS names.
LVL 44

Expert Comment

by:Adam Brown
ID: 41873143
Then you will likely not be able to eliminate the certificate error if you want to continue using certificate validation when connecting to wireless. The solution, though, would be to disable the setting to Validate Server Certificates in the wireless profile on the client machines. That would effectively prevent the error from popping up, but could put your client machines at risk of being hijacked by a rogue AP using the same SSID as yours and its own RADIUS authentication mechanism (The likelihood of this type of thing is remote, since it requires physical access and wouldn't actually allow attacker to compromise your network, but it could lead to some operational issues, and I like to make sure people understand the potential impact of a configuration setting modification like this).

Accepted Solution

polaris101 earned 0 total points
ID: 41878862
The solution was to use an internal CA and make sure the NPS Server name matched the certificate name.  Unfortunately, since the domain is a .local this only works for domain computers.  We'll have to educate users about looking at the certificates they are trusting for the other devices.

Author Closing Comment

ID: 41885231
Found answer on Ubiquiti Support Forum

Featured Post

Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
What monsters are hiding in your child's room? In this article I will share with you a tech horror story that could happen to anyone, along with some tips on how you can prevent it from happening to you.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question