Once the RADIUS profile is created and all the server information is connected, you will be asked to upload a certificate on the summary page.
To access the Wi-Fi network, each user must authenticate using a user certificate (client certificate) issued and signed by the Certificate Authority (CA) configured by your administrator.
This CA has two parts:
- Private key - Used to sign the user certificates
- Public key - Used by Zoho Directory to validate these signatures
To upload the CA certificate
- Click Upload Certificate under Summary page, you are directed to the Certificates tab.
- Upload or drag and drop your CA public key certificate from your local storage.
- Click Upload.
Once the CA certificate is uploaded, any user certificate signed by this CA can be validated during EAP-TLS authentication.
The uploaded certificate should contain only the CA's public certificate. Never upload the CA private key.
To assign users
- Click the RADIUS Clients tab.
- Select the configured RADIUS client and click Assign Members.
- Choose users from the dropdown and click Assign. You can assign groups or choose for everyone.
For example, if John Smith (
john.smith@zylker.com) is assigned to this configuration, they can access the network using EAP-TLS only if their user certificate contains their email address (
john.smith@zylker.com) in the SAN field, and is signed by the uploaded CA certificate.