Certificate Issues
Certificate Chain Not Trusted
If you receive an error that indicates the certificate chain is not trusted, verify that you have the public certificate and any intermediate certificates for the root CA.
Common Name in Template
The CN in the certificate template may need to include domain information. This can be specified as ${USERNAME}@domain within Cloudpath on the specific certificate template.
SAN Other Name in Certificate Template
If the RADIUS or NPS logs show an issue with credentials, check the SAN Other Name Pattern in the certificate template. The variable listed in the SAN Other Name Pattern field should match the variable used in the Common Name Pattern field.
Missing EKU in the RADIUS Server Certificate
RADIUS certificates must contain Microsoft Server EKU-1.3.6.1.5.5.7.3.1. When you create the server certificate template in Cloudpath, you must check the box for the Microsoft Server EKU.