Staff laptops failing 802.1X after the RADIUS certificate renewal
Cause. The RADIUS server certificate was renewed from a new intermediate CA. Laptops still on the older wireless profile trusted only the previous intermediate, so they rejected the new chain during EAP-TLS and never sent their own certificate. Capture radius-eap.pcapng shows those clients ending the TLS handshake with an unknown_ca alert straight after the server’s Certificate message; laptops on the newer profile complete it.
Fix. Pushed an updated wireless profile that trusts the issuing root and names the RADIUS server, rather than pinning one intermediate, through the existing device management with site IT’s agreement. Verified: the affected laptops authenticate and land on the staff VLAN, and the RADIUS log shows EAP-TLS success for each device that had been failing.
Caught earlier next time. Added a NOC rule to alert when EAP-TLS rejects rise above their normal level for more than 10 minutes, and a change-checklist step to test the profile against any renewed RADIUS certificate before it goes live.

ARTA CYBER