<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Troubleshooting DOT1x WLAN / EAP-TLS &amp;quot;Unknown CA&amp;quot; Error seen in RADIUS Access-Request in wireshark in RUCKUS Self-Help</title>
    <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Troubleshooting-DOT1x-WLAN-EAP-TLS-quot-Unknown-CA-quot-Error/m-p/61966#M171</link>
    <description>&lt;P&gt;&lt;SPAN&gt;When working with RADIUS, Network Policy Server (NPS), and implementing DOT1x authentication using EAP-TLS, you might encounter an error message in the packet capture stating &lt;STRONG&gt;"Unknown CA."&lt;/STRONG&gt; This error typically occurs when the certificate authority (CA) responsible for issuing the server's certificate is not recognized or trusted by the client.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Symptom:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Computer fails to connect to the dot1x wireless network.
&lt;UL&gt;
&lt;LI&gt;Taking a &lt;STRONG&gt;packet capture&lt;/STRONG&gt; on the interface of the NPS server, an "Unknown CA" error is seen in the &lt;STRONG&gt;RADIUS Access-Request packet&lt;/STRONG&gt; sent to the server during the authentication process.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Orlando_Elias_0-1688152015724.png" style="width: 651px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/7250iFE3E798FF5D63D94/image-dimensions/651x344/is-moderation-mode/true?v=v2" width="651" height="344" role="button" title="Orlando_Elias_0-1688152015724.png" alt="Orlando_Elias_0-1688152015724.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Troubleshooting Steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Test with a Different User Account:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Attempt to connect to the wireless network using a different user account on the same computer.&lt;/LI&gt;
&lt;LI&gt;Determine if the "Unknown CA" error persists for the alternate user.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Run the 'gpupdate' Command on Windows Computer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Open Command Prompt as an administrator.&lt;/LI&gt;
&lt;LI&gt;Execute the following command: gpupdate /force&lt;/LI&gt;
&lt;LI&gt;Allow the Group Policy update to complete and restart the computer if necessary.&lt;/LI&gt;
&lt;LI&gt;Retry connecting to the wireless network and observe if the error persists.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Check Certificates on the Windows Machine:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Press Windows Key + R, type "certmgr.msc," and press Enter.&lt;/LI&gt;
&lt;LI&gt;In the Certificate Manager window, expand the "Trusted Root Certification Authorities" folder.&lt;/LI&gt;
&lt;LI&gt;Verify if the certificate authority (CA) responsible for issuing the server's certificate is present in the list.&lt;/LI&gt;
&lt;LI&gt;If the CA is missing, you may need to import the CA's root certificate into the "Trusted Root Certification Authorities" store.&lt;/LI&gt;
&lt;LI&gt;Restart the computer after importing the CA's root certificate if necessary.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Additional Troubleshooting Steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review the NPS server configuration and ensure the correct server certificate is being used.&lt;/LI&gt;
&lt;LI&gt;Verify the validity and expiration of the server's certificate.&lt;/LI&gt;
&lt;LI&gt;Check if the client's operating system is up to date with the latest security patches.&lt;/LI&gt;
&lt;LI&gt;Reboot the NPS server or servers&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Shut me a question for further guidance.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2023 14:08:54 GMT</pubDate>
    <dc:creator>Orlando_Elias</dc:creator>
    <dc:date>2023-07-12T14:08:54Z</dc:date>
    <item>
      <title>Troubleshooting DOT1x WLAN / EAP-TLS "Unknown CA" Error seen in RADIUS Access-Request in wireshark</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Troubleshooting-DOT1x-WLAN-EAP-TLS-quot-Unknown-CA-quot-Error/m-p/61966#M171</link>
      <description>&lt;P&gt;&lt;SPAN&gt;When working with RADIUS, Network Policy Server (NPS), and implementing DOT1x authentication using EAP-TLS, you might encounter an error message in the packet capture stating &lt;STRONG&gt;"Unknown CA."&lt;/STRONG&gt; This error typically occurs when the certificate authority (CA) responsible for issuing the server's certificate is not recognized or trusted by the client.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Symptom:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Computer fails to connect to the dot1x wireless network.
&lt;UL&gt;
&lt;LI&gt;Taking a &lt;STRONG&gt;packet capture&lt;/STRONG&gt; on the interface of the NPS server, an "Unknown CA" error is seen in the &lt;STRONG&gt;RADIUS Access-Request packet&lt;/STRONG&gt; sent to the server during the authentication process.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Orlando_Elias_0-1688152015724.png" style="width: 651px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/7250iFE3E798FF5D63D94/image-dimensions/651x344/is-moderation-mode/true?v=v2" width="651" height="344" role="button" title="Orlando_Elias_0-1688152015724.png" alt="Orlando_Elias_0-1688152015724.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Troubleshooting Steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Test with a Different User Account:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Attempt to connect to the wireless network using a different user account on the same computer.&lt;/LI&gt;
&lt;LI&gt;Determine if the "Unknown CA" error persists for the alternate user.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Run the 'gpupdate' Command on Windows Computer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Open Command Prompt as an administrator.&lt;/LI&gt;
&lt;LI&gt;Execute the following command: gpupdate /force&lt;/LI&gt;
&lt;LI&gt;Allow the Group Policy update to complete and restart the computer if necessary.&lt;/LI&gt;
&lt;LI&gt;Retry connecting to the wireless network and observe if the error persists.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Check Certificates on the Windows Machine:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Press Windows Key + R, type "certmgr.msc," and press Enter.&lt;/LI&gt;
&lt;LI&gt;In the Certificate Manager window, expand the "Trusted Root Certification Authorities" folder.&lt;/LI&gt;
&lt;LI&gt;Verify if the certificate authority (CA) responsible for issuing the server's certificate is present in the list.&lt;/LI&gt;
&lt;LI&gt;If the CA is missing, you may need to import the CA's root certificate into the "Trusted Root Certification Authorities" store.&lt;/LI&gt;
&lt;LI&gt;Restart the computer after importing the CA's root certificate if necessary.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Additional Troubleshooting Steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review the NPS server configuration and ensure the correct server certificate is being used.&lt;/LI&gt;
&lt;LI&gt;Verify the validity and expiration of the server's certificate.&lt;/LI&gt;
&lt;LI&gt;Check if the client's operating system is up to date with the latest security patches.&lt;/LI&gt;
&lt;LI&gt;Reboot the NPS server or servers&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Shut me a question for further guidance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 14:08:54 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Troubleshooting-DOT1x-WLAN-EAP-TLS-quot-Unknown-CA-quot-Error/m-p/61966#M171</guid>
      <dc:creator>Orlando_Elias</dc:creator>
      <dc:date>2023-07-12T14:08:54Z</dc:date>
    </item>
  </channel>
</rss>

