07-11-2019 12:38 AM
I have Windows 2012 NPS with CA - AD CS- I am trying to setup PKI from scratch: CA ROOT then Enterprise Subordinates with CA, web etc. I have noticed when I remove CA from NPS radius stopped working. Is there any pace pointing to CA server?
07-11-2019 03:28 PM
I use cloud.aerohive.com - and we are currently building PKI CA infrastructure so definitely I want to use that. Using godaddy cert is always an option but I try to stay away from that.
07-11-2019 02:18 PM
You can create a self signed certificate within HiveManager (if you're interested in this and you can tell me which HiveManager platform you are using (see guide below to determine this), I can give more details on how to do this), or you can purchase a third party certificate from a certificate authority(CA) such as GoDaddy.
Using a self signed certificate is not as secure as a third party certificate from a CA, and self signed certificates will still present a warning to end users that the site is not verified as safe.
If you're using a third party certificate, you'll want to make sure the CA gives you the Cert file (the file that has the domain name), the Server Cert file, and the Key file. If these are given as separate files, you'd want to concatenate them in to one file to import it in to HiveManager.
This guide will walk you through how to determine which HiveManager you are using, for reference: https://thehivecommunity.aerohive.com/s/article/Which-HiveManager-Platform-am-I-using
07-11-2019 02:10 PM
Sorry for my question. let's imagine I am starting with 802.1X and want to create certificate for it - do you have any documentation how to build such certificate? I am using Windows PKI infrastructure. How that certificate should look like?
07-11-2019 01:26 PM
I'm sorry, I'm not sure what you mean by "Is there any pace pointing to CA server", but our Radius set up would need to know what certificates to use, and if a change is made on the NPS side of things that isn't also reflected in the Radius setup within the HiveManager, then you would see Radius connections failing.