WAP-Enterprise 802.11x Certificate Revoked but device can still Auth
WAP-Enterprise 802.11x Certificate Revoked but device can still Auth
Tags:
#radius
We have freeRadius running and working with TLS Certificate Auth. When we revoke the certificate the client can still acces the network even after rebooting the freeRadius .
Rebooting the access point resolves this and clients get rejected due to certificate revoked.
We have all cacheing disabled in freeRadius and have been informed that if freeRadius reboots then the AP is doing the cacheing.
How can we resolve this?
Research show the AP is holding on to some sort of PMKSA cache.
