NPS CA certificate expired, I recreated cert and still receiving an error.

Rich Baker 20 Reputation points
2023-03-30T19:06:39.23+00:00

Hello,

I have a server that is the CA for the domain. It's CA certificate expired yesterday. I have recreated the certificate. Local certificate for the server expires in 1 year, the certificate for the CA in 5 years. I have changed the NPS EAP properties to the new local certificate. But when my clients try to authenticate I still get the following.

Connection Request Policy Name: Secure Wireless Connection

Network Policy Name: -

Authentication Provider: Windows

Authentication Server. CAServer.domain.lan

Authentication Type: PEAP

EAP Type: -

Account Session Identifier: 38303533304241454532414435364344

Logging Results: Accounting information was written to the local log file.

Reason Code: 262

Reason: The supplied message is incomplete. The signature was not verified.

How do I get around this?

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. JimmySalian-2011 42,511 Reputation points
    2023-03-30T19:12:34.7766667+00:00

    Hi,

    Did you distribute and publish the CA Certificate to the clients? As the clients might still be using old Certificate so you need to distribute and publish in AD, also you need to publish the CRL to the distribution points - CRL and AA.

    Hope this helps.

    JS

    ==

    Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Rich Baker 20 Reputation points
    2023-03-30T20:07:38.4633333+00:00

    I was able to get it fixed, because the certificate had expired and the wireless PC's were not connected to the domain. We exported the new certificate, put it on a flash drive and imported the certificate on the disconnected PC's. PC's are now able to authenticate via Radius using the wireless.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.