Quick troubleshooting view
Certificate-based 802.1X authentication fails for all or many clients.
- Read RADIUS logs
- Check server certificate and EKU
- Test revocation
- Correct only the component confirmed by the checks
- Retest the original symptom after the change
- Escalate with collected evidence when the cause remains unclear
Contextual technician plan
Perform this check and preserve the observed result before changing configuration.
“Read RADIUS logs” should produce an observation that clearly confirms or rules out “Expired RADIUS certificate”.
If the observation is normal, lower “Expired RADIUS certificate” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Expired RADIUS certificate” first. Related action: Correct only the component confirmed by the checks.
Perform this check and preserve the observed result before changing configuration.
“Check server certificate and EKU” should produce an observation that clearly confirms or rules out “Untrusted PKI chain”.
If the observation is normal, lower “Untrusted PKI chain” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Untrusted PKI chain” first. Related action: Retest the original symptom after the change.
Perform this check and preserve the observed result before changing configuration.
“Test revocation” should produce an observation that clearly confirms or rules out “Unreachable CRL”.
If the observation is normal, lower “Unreachable CRL” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Unreachable CRL” first. Related action: Escalate with collected evidence when the cause remains unclear.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Escalate with the exact symptom, scope, timestamp and completed checks when the issue remains unresolved.
+Open the complete detailed guideDetailed explanations and original troubleshooting content.
Certificate-based 802.1X authentication fails for all or many clients.
Likely causes
- Expired RADIUS certificate
- Untrusted PKI chain
- Unreachable CRL
- Changed RADIUS policy
Checks in priority order
- Read RADIUS logs
- Check server certificate and EKU
- Test revocation
- Compare with a previously successful authentication
When to escalate
Escalate when the failure affects multiple users, a production dependency is unavailable, or logs show a component outside your control. Include timestamps, scope, tests already performed, and the last known working state.