EAP-TLS certificate renewal

Renew EAP-TLS Client and Server certificate Authorities

This guide outlines the necessary steps for renewing Client and/pr Server Certificate Authorities (CAs) in the EAP-TLS configuration. These steps are critical when certificates are nearing expiration to maintain uninterrupted services.

Renewing the Client CA

  1. Navigate to the Foxpass console's EAP-TLS page.
  2. Click on the “Create New CA” button under the section labeled “Client Certificate Authorities.”
Create new Client CA

Create new Client CA

  1. A new Client CA will be created. Click 'Ok'.
Client CA created

Client CA created

  1. All new client certificates will be signed by the new Client CA you just created. Do not delete the old CA until after it has expired; if you delete it early all of the certificates that it has signed will immediately become invalid.

Renewing Server Certificates

  1. Navigate to the Foxpass console's EAP-TLS page.
  2. Find the newest Server CA
  3. Click on the 'Create Certificate' button.
Create Certificate

Create Certificate

Certificate created

Certificate created

Renewing Server CA Certificates

  1. Navigate to the Foxpass console's EAP-TLS page.
  2. Click on “Create New Server CA” under the section labeled "Server Certificate Authorities".
Create new Server CA

Create new Server CA

  1. A new Server CA will be created. Click 'Ok'.
Server CA created

Server CA created

  1. Click on the 'Create Certificate' button.

    Create Certificate

    Create Certificate

    Certificate created

    Certificate created

  2. Click on 'Set as Active' button.

Mark Server CA as active

Mark Server CA as active

Click Ok

Click Ok

CA marked as active

CA marked as active

Additional Steps for MDM Environments

If you are using a Mobile Device Management (MDM) solution such as Intune / Apple Configurator / JAMF / Chromebook etc., you will have to replace the existing client CA in your profile with the new one. However, you should add (not replace) the new server CA to your existing profile.

Timely renewal of Client and Server CA certificates is essential for the security and functionality of your EAP-TLS setup. Make sure to follow the steps as soon as you receive an email from Foxpass that certificates are nearing their expiration date.