Tips and Troubleshooting
Validate Server Certificate Setting in the License Server
When testing your configuration, begin with the validate server certificate setting unchecked on the Cloudpath system. This allows you to troubleshoot any certificate configuration issues for the EAPTLS/ PEAP protocol. After it is successful, enable the validate server certificate setting in Cloudpath.
After the certificate has been validated, the Network Policy Server (NPS) looks up the name on the certificate in AD and applies network policy.
LDAP
Using LDAP's default port (TCP-389) with a Base DN of the parent Active Directory domain will only show objects from the parent domain. Change the port to 3268, but keep the same Base DN to allow LDAP access to users from the child AD domain (Reference http://technet.microsoft.com/enus/library/cc978012.aspx).
Global Catalog queries are directed to port 3268, which explicitly indicates that Global Catalog semantics are required. By default, ordinary LDAP searches are received through port 389. If you bind to port 389, even if you bind to a Global Catalog server, your search includes a single domain directory partition. If you bind to port 3268, your search includes all directory partitions in the forest. If the server you attempt to bind to over port 3268 is not a Global Catalog server, the server refuses the bind.
OSCP Issues
The NPS server first attempts to validate a client certificate using the Online Certificate Status Protocol (OSCP). If the OSCP validation is successful, the validation verification is satisfied; otherwise, it attempts to perform a CRL validation of the user or computer certificate.
OCSP provides the ability to revoke certificates. However, if using OCSP affects the performance of your system, you could disable OCSP and use CRL only.
Certificate revocation checking behavior for NPS can be modified with registry settings (http:// technet.microsoft.com/en-us/library/cc771995%28v=ws.10%29.aspx).
When the client fetches the OCSP response from the CA, it looks up the domain name of the CA's OCSP server in the DNS, as well as establishing a connection to the OCSP server.
If you receive a message that indicates the server cannot resolve the OSCP URL, check the hostname listed in the OSCP URL for the onboard Root CA you created in Cloudpath. See Create the Certificate Authority. You might need to add this hostname to the DNS of the domain.
Credentials Mismatch
If you receive an error that an authentication failed due to a user credentials mismatch, either the user name provided does not map to an existing user account, or the password was incorrect.
Certificate Template Issues
The CN in the certificate template may need to include domain information. This can be specified as ${USERNAME}@domain within Cloudpath on the specific certificate template.
If the NPS logs show an issue with credentials, check the SAN Other Name Pattern in the certificate template. The variable listed in the SAN Other Name Pattern field should match the variable used in the Common Name Pattern field.
Missing EKU in the RADIUS Server Certificate
RADIUS certificates must contain Microsoft Server EKU-1.3.6.1.5.5.7.3.1. When you create the server certificate template in Cloudpath, you must check the box for the Microsoft Server EKU. See Set Up Certificate Template Settings For NPS for more information.
EAP Method is Not Available on the Server
If you are receiving a message that the EAP message is not available on the server, check the following configuration issues.
Register the NPS With the Domain
If the NPS is not registered to the domain, you might receive an error message that the EAP method is not available on the server.
To see if the NPS is registered with the domain, right-click the NPS server. If the server is registered, the Register with domain option is not available.
If there is a problem with your working registration, try deleting and re-adding the registration using the NPS Administrator prompt and the commands in this example:
net stop ias netsh ras delete registeredserver domain=x server=y net start ias net stop ias netsh ras add registeredserver domain=samplecorp.local server=SAMPLE-NPS-Server net start ias
RADIUS Server Certificate Missing Private Key
If the RADIUS server certificate is missing the private key, you might receive an error message that the EAP Method is not available on the server, you might be missing the private key for the RADIUS server certificate.
Be sure that the RADIUS server certificate in the Local Computer Personal Certificate
Store shows the
certificate with key
icon
next to it. This indicates that the certificate is signed with the private key. If it does not show the icon, you do not have the private key for the RADIUS certificate. Try downloading the RADIUS certificate and private key in P12 format.
See Download the RADIUS Server Certificate for instructions on downloading the certificate from Cloudpath, or use the following command examples from the NPS Administrator prompt:
certutil -dspublish -f root.cer NTAuthCA certutil -enterprise -addstore NTAuth root.cer
Certificate Chain Not Trusted
If you receive an error that indicates the certificate chain is not trusted, verify that you have the public certificate and any intermediate certificates for the root CA. See Download the Public Key of the Intermediate CA for more information.