EAP-TLS certificate renewal
Renew EAP-TLS Client and Server certificate Authorities
This guide outlines the necessary steps for renewing Client and/or Server Certificate Authorities (CAs) in the EAP-TLS configuration. These steps are critical when certificates are nearing expiration to maintain uninterrupted services.
Renewing the Client CA
- Navigate to the Foxpass console's EAP-TLS page.
- Click on the “Create New CA” button under the section labeled “Client Certificate Authorities.”
- A new Client CA will be created. Click 'Ok'.
- Wait about 10 minutes for this new Client CA to be available on our RADIUS servers.
- Go to the SCEP page.
- Edit the SCEP endpoint(s) that should begin using this new Client CA. The last option on the modal is the Client CA that will be used for this SCEP endpoint. Click 'Submit' button.
- Look at your MDM's SCEP configuration profile. If it makes reference to the Client CA, then download your new Client CA and replace what's there with the new downloaded one.
- Do not delete the old CA until after it has expired OR you are sure all devices have received a certificate using the new CA; if you delete it early all of the certificates that it has signed will immediately become invalid.
Renewing Server Certificates
- Navigate to the Foxpass console's EAP-TLS page.
- Find the newest Server CA
- Click on the 'Create Certificate' button.
Renewing Server CA Certificates
- Navigate to the Foxpass console's EAP-TLS page.
- Click on “Create New Server CA” under the section labeled "Server Certificate Authorities".
- A new Server CA will be created. Click 'Ok'.
-
Click on the 'Create Certificate' button.
-
Download the new Server CA.
-
Upload the new Server CA to your MDM.
-
Modify the MDM's WiFi configuration profile to trust both the existing Server CA and the new one.
-
Wait until the MDM profile has been pushed to all devices.
-
Click on 'Set as Active' button in Foxpass.
Updated 9 days ago