EAP-TLS certificate renewal
Renew EAP-TLS Client and Server certificate Authorities
This guide outlines the necessary steps for renewing Client and/or Server Certificate Authorities (CAs) in the EAP-TLS configuration. These steps are critical when certificates are nearing expiration to maintain uninterrupted services.
Renewing the Client CA
- Navigate to the Foxpass console's EAP-TLS page.
- Click on the “Create New CA” button under the section labeled “Client Certificate Authorities.”
- A new Client CA will be created. Click 'Ok'.
- Wait about 10 minutes for this new Client CA to be available on our RADIUS servers.
- Go to the SCEP page.
- Edit the SCEP endpoint(s) that should begin using this new Client CA. The last option on the modal is the Client CA that will be used for this SCEP endpoint. Click 'Submit' button.
- Do not delete the old CA until after it has expired OR you are sure all devices have received a certificate using the new CA; if you delete it early all of the certificates that it has signed will immediately become invalid.
Renewing Server Certificates
- Navigate to the Foxpass console's EAP-TLS page.
- Find the newest Server CA
- Click on the 'Create Certificate' button.
Renewing Server CA Certificates
- Navigate to the Foxpass console's EAP-TLS page.
- Click on “Create New Server CA” under the section labeled "Server Certificate Authorities".
- A new Server CA will be created. Click 'Ok'.
-
Click on the 'Create Certificate' button.
-
Click on 'Set as Active' button.
Additional Steps for MDM Environments
If you are using a Mobile Device Management (MDM) solution such as Intune / Apple Configurator / JAMF / Chromebook etc., you will have to replace the existing client CA in your profile with the new one. However, you should add (not replace) the new server CA to your existing profile.
Timely renewal of Client and Server CA certificates is essential for the security and functionality of your EAP-TLS setup. Make sure to follow the steps as soon as you receive an email from Foxpass that certificates are nearing their expiration date.
Updated 6 months ago