Bypassing Server Certificate Validation for Troubleshooting (2024)

Table of Contents
Windows 7/8 Windows 10/11 MacOS
  1. Last updated
  2. Save as PDF

​A fundamental component of RADIUS is a client's validation of the RADIUS server's identity. This is accomplished by hosting a certificate on the RADIUS server that has been validated by a trusted Certificate Authority (CA). If a self-signed certificate(or any certificate from an untrustedCA) is in use, most clients will reject the connection since they cannot validate the server's identity.

For troubleshooting purposes, server certificate validation can be disabled on one or multiple clients, allowing those clients to connect regardless of the certificate in use.

Note:It is strongly recommended to address this issue by using a trusted certificate. Disabling server validation as a permanent resolution introduces security risks on the network.

Windows 7/8

To disable the validation of server certificates in Windows 7/8:

  1. Navigate to Control Panel > Network and Sharing Center > Manage wireless networks.
    Note: If presented with different options, switch from View by Categories to either small or large icons.
  2. Right-click the interface/network in question and choose Properties.
  3. On the Securitytab, click Settings.
  4. Along the top, uncheck the box for Validate server certificate.

Windows 10/11

  1. Navigate toControl Panel > Network andSharing Center> Change adapter settings.
    Note: If presented with different options, switch from View by Categories to either small or large icons.
  2. Double-click the interface/network in question and choose Properties.
  3. On the Authentication tab, click Settings.
  4. Along the top, uncheck the box for Verify the server's identity by validating the certificate.

MacOS

If using OS X, sometimes it can take up to 10 seconds for authentication to complete. This can occur if theRADIUS certificate, or any certificate in the chain, is configured for CRL or OCSP. Please refer to Apple supportfor more details.

For additional information on MerakiRADIUS configuration, please refer to the following article:

Bypassing Server Certificate Validation for Troubleshooting (2024)
Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6073

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.