Upload the CA certificate - Admin Panel | RADIUS

Upload the CA certificate

Once the RADIUS profile is created and all the server information is connected, you will be asked to upload a certificate on the summary page.

To access the Wi-Fi network, each user must authenticate using a user certificate (client certificate) issued and signed by the Certificate Authority (CA) configured by your administrator.

This CA has two parts:
  1. Private key - Used to sign the user certificates
  2. Public key - Used by Zoho Directory to validate these signatures

To upload the CA certificate

  1. Click Upload Certificate under Summary page, you are directed to the Certificates tab.
  2. Upload or drag and drop your CA public key certificate from your local storage.
  3. Click Upload.
Once the CA certificate is uploaded, any user certificate signed by this CA can be validated during EAP-TLS authentication.
Notes
 The uploaded certificate should contain only the CA's public certificate. Never upload the CA private key.

To assign users

  1. Click the RADIUS Clients tab.
  2. Select the configured RADIUS client and click Assign Members.
  3. Choose users from the dropdown and click Assign. You can assign groups or choose for everyone.
For example, if John Smith (john.smith@zylker.com) is assigned to this configuration, they can access the network using EAP-TLS only if their user certificate contains their email address (john.smith@zylker.com) in the SAN field, and is signed by the uploaded CA certificate.