HPE7-A08 · Question #89
You configured a mixed-mode SSID with WPA3-Enterprise and EAP-TLS security. When you connect a client, HPE Aruba Networking ClearPass shows the following error: What is needed to resolve this issue?
The correct answer is D. Configure ClearPass to trust the client certificate. In EAP-TLS, authentication is mutual - both the client and the RADIUS server (ClearPass) must present and validate certificates. The error indicates ClearPass cannot validate the client's certificate because it doesn't trust the Certificate Authority (CA) that issued it; adding…
Question
You configured a mixed-mode SSID with WPA3-Enterprise and EAP-TLS security. When you connect a client, HPE Aruba Networking ClearPass shows the following error:
What is needed to resolve this issue?
Exhibit
Options
- AConfigure the client to trust the ClearPass server certificate
- BEnable WPA3 transition mode on the SSID
- CInstall a trusted server certificate from a well-known public CA on your ClearPass server
- DConfigure ClearPass to trust the client certificate
How the community answered
(30 responses)- A3% (1)
- B3% (1)
- C10% (3)
- D83% (25)
Explanation
In EAP-TLS, authentication is mutual - both the client and the RADIUS server (ClearPass) must present and validate certificates. The error indicates ClearPass cannot validate the client's certificate because it doesn't trust the Certificate Authority (CA) that issued it; adding that CA to ClearPass's trusted certificate store resolves the failure.
Why the distractors are wrong:
- A addresses the opposite problem - the client distrusting the server certificate, not ClearPass distrusting the client certificate.
- B (WPA3 transition mode) controls WPA2/WPA3 coexistence on the SSID - irrelevant to a certificate validation failure.
- C is a red herring: EAP-TLS server certificates in enterprise environments routinely use private/internal CAs, not public ones, and changing the server certificate doesn't fix ClearPass's inability to validate the client certificate.
Memory tip: In EAP-TLS, ask "whose cert is being rejected?" - the error comes from ClearPass (the server), which means ClearPass doesn't trust something. The only thing ClearPass receives from the client is the client certificate, so the fix is always on the ClearPass trust store side (option D).
Topics
Community Discussion
No community discussion yet for this question.
