cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
623
Views
0
Helpful
2
Replies

Replace Radius Certificate, best way?

patoberli
VIP Alumni
VIP Alumni

Hi

We currently have a deployment of a WCS, two WiSMs, some 80 APs and around 1000 Clients. They authenticate with WPA2-PEAP against two Cisco ACS Servers. The ACS have valid server certificates. The Clients use all available operating systems on the market.

I need now to replace the ACS servers with new Windows Radius servers. The new Radius servers also use new certificates from a different reseller. My tests with a test SSID have shown that I need to delete and recreate the connection profile in Windows 7, to be able to connect after the Radius change.

Any good way on how to achieve the exchange, without making to much work on the client side?

The clients are all private machines (education), so we can't really deploy anything on them.

Thanks,

pato

2 Replies 2

George Stefanick
VIP Alumni
VIP Alumni

Why can you not use the same cert from the ACS? Are your clients vailidating certs?

"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
___________________________________________________________

The servers have new hostnames, so the Certs would be probably not anymore valid.

If you add the Wlan to Windows7 by selecting it and click connect, it will automatically put the Validate Option on.

I guess I won't come around to inform the users to delete and recreate the connection.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card