Symptoms: After replacing the RADIUS certificate:
Existing wireless clients are unable to reconnect. New wireless clients fail authentication, even after accepting the presented certificate. Restarting services or rebooting infrastructure components does not resolve the issue. The certificate import appears successful, but only the server certificate is visible. Intermediate or Root CA certificates do not appear to be associated with the certificate chain. Wireless authentication failures continue until the previous certificate configuration is restored.
Cause:
The issue may occur when the certificate chain is not properly imported or applied while the RADIUS service is running. In HA deployments, certificate synchronization between nodes may also result in incomplete or inconsistent certificate chain replication.
As a result, the RADIUS server may present an incomplete certificate chain during the EAP authentication process, causing client validation failures.
To correctly install and apply the renewed certificate chain:
Stop the RADIUS service:
Before importing the certificate:
Upload the certificate chain:
Import the complete certificate chain, including:
Verify that the complete certificate chain is present after the import operation.
Start the RADIUS service:
After the certificate chain has been imported successfully:
HA deployments:
In FortiNAC Versions Earlier than v7.6.3:
If the FortiNAC deployment is configured for HA and is running a version earlier than v7.6.3:
Temporarily break the HA relationship and place both appliances in standalone mode. Install and verify the certificate chain on each node individually. Rebuild HA from the primary node only after confirming the certificate chain is correctly installed on both nodes. Verify that certificates are replicated successfully after HA synchronization completes.
FortiNAC v7.6.3 GA and later: Starting with FortiNAC-F v7.6.3 GA, administrators can install certificates on the secondary HA node directly from the primary node GUI.
When replacing certificates in an HA deployment:
Install the certificate chain on the primary node. Use the HA management functionality from the primary node GUI to deploy the certificate to the secondary node. Verify that the certificate and complete chain are present on both HA members. Confirm successful HA synchronization after deployment.
Validate authentication.
Perform authentication testing using multiple wireless clients and verify:
WPA2-Enterprise authentication succeeds. The complete certificate chain is presented. Client certificate validation completes successfully. Wireless connectivity is restored.
Verification:
The issue is considered resolved when:
The complete certificate chain is visible and correctly associated with the server certificate. Wireless clients authenticate successfully through WPA2-Enterprise. Authentication succeeds for both existing and newly connecting devices. Certificate synchronization completes successfully across all HA nodes.
Important notes:
Certificate imports may not be applied correctly while the RADIUS service is running. If only the server certificate appears after import, the certificate chain may not have been fully installed. In HA deployments running versions earlier than v7.6.3, verify certificate integrity on each node before rebuilding HA. In FortiNAC-F v7.6.3 GA and later, certificate deployment to the secondary node can be performed directly from the primary node GUI. When using certificate chains that require intermediate or cross-signed root CA certificates, ensure all required certificates are imported as part of the chain. Always validate wireless authentication after certificate replacement and HA synchronization.
Related articles:
|