{"id":75223,"date":"2023-06-05T13:12:07","date_gmt":"2023-06-05T17:12:07","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=75223"},"modified":"2024-06-26T14:21:17","modified_gmt":"2024-06-26T18:21:17","slug":"update-radius-certificates-for-eap-ttls-systems","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/update-radius-certificates-for-eap-ttls-systems","title":{"rendered":"Update RADIUS Certificates for EAP-TTLS Devices"},"content":{"rendered":"\n
JumpCloud’s RADIUS-as-a-Service offers Certificate-based methods for desktops, laptops, and mobile devices to verify that they are authenticating to the correct RADIUS server (so that no one else can pretend to be JumpCloud’s RADIUS server). This will prevent clients from trusting RADIUS servers without the Private Key that matches this Certificate. JumpCloud strongly recommends that you leverage a certificate authentication method for this reason.
This help article explains how to update and deploy the new JumpCloud RADIUS certificate to both Windows and Mac devices.<\/p>\n\n\n\n
<\/p><\/div>
The certificate is required<\/strong> for EAP-TTLS\/PAP authentication methods, and for some PEAP clients as well. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Most clients using PEAP do not need to manually add the RADIUS certificate because it is automatically acquired during the device authentication process. <\/p><\/div> Considerations<\/strong>:<\/p>\n\n\n\n <\/p><\/div> Make sure you have a current RADIUS certificate installed. For more information, see Configure EAP-TTLS\/PAP on Mac & iOS for RADIUS<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To update the JumpCloud RADIUS certificate in macOS:<\/strong><\/p>\n\n\n\n <\/p><\/div> <\/p><\/div> <\/p><\/div> Make sure you have a current RADIUS certificate installed. For more information, see EAP-TTLS\/PAP Initial Configuration on Windows for JumpCloud RADIUS clients<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To update the JumpCloud RADIUS certificate in Windows 10:<\/strong><\/p>\n\n\n\n <\/p><\/div> The new certificate will be downloaded as part of the Powershell process.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n <\/p><\/div> Alternatively, you can download and import the new certificate manually from the command line, as shown in the following example:<\/p>\n\n\n\n Import-Certificate -FilePath To configure your wireless network<\/strong>:<\/p>\n\n\n\n As a reference, the Mac and Windows commands, as well as the new certificate and its signature can be obtained here:<\/p>\n\n\n\n
<\/p>\n\n\n\n\n
\n
\n
Mac Setup<\/h2>\n\n\n\n
\n
.mobileconfig<\/code> file and open it in a text editor.<\/li>\n<\/ol>\n\n\n\n
\n
.mobileconfig<\/code> file contains the updated certificate.<\/li>\n\n\n\n
.mobileconfig<\/code> file is not compatible with iOS\/iPadOS. Users on these devices should reconnect to the RADIUS network SSID manually, which will cause a prompt for the user to download and trust the new RADIUS certificate.<\/li>\n<\/ul>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n
<\/li>\n<\/ol>\n\n\n\n\n
.mobileconfig<\/code> file.<\/li>\n\n\n\n
\n
Windows Setup<\/h2>\n\n\n\n
\n
radius_cert_install-2024.ps1<\/code><\/strong> file.<\/li>\n<\/ol>\n\n\n\n
\n
\n
\n
“C:\\Windows\\Temp\\radius.jumpcloud.com-2024.crt”
-CertStoreLocation Cert:\\LocalMachine\\Root<\/p>\n<\/div><\/div>\n\n\n\nWireless Network Configuration <\/h3>\n\n\n\n
\n
radius.jumpcloud.com<\/code> and the new<\/em> imported<\/em> certificate are selected.<\/li>\n\n\n\n
Reference Files<\/h2>\n\n\n\n