When configuring 802.1X certificate authentication, you need to deploy a CA certificate server first. How do you deploy a CA certificate server?
Here's the answer.
Open a browser and enter https://Server-IP/certsrv, where Server-IP indicates the IP address of the CA certificate server.
If the following page is displayed after login using the AD domain account administrator and its password, the CA server functions properly. Otherwise, delete and then add the CA component again.

On Certification Authority, right-click the root certificate. In the displayed dialog box, click the Extensions tab and check extended fields CDP and AIA.
CDP: Include in the CDP extension of issued certificates must be selected for LDAP and HTTP.
AIA: The two options in the red box must be selected for the OCSP URL.


Open a browser and enter https://Server-IP/certsrv/mscep_admin, where Server-IP indicates the IP address of the CA certificate server.
If the following page is displayed after login using the AD domain account administrator and its password, the SCEP and HTTPS settings are correct.
If the page is displayed in HTTP mode but cannot be displayed in HTTPS mode, check whether HTTPS is bound to the certificate, and whether the correct root certificate is selected. Select the certificate the same as the full computer name for SSL certificate.
If the page cannot be displayed in HTTP mode, check whether Network Device Enrollment Service is Installed.

The SCEP template must contain the Client Authentication field. Otherwise, end users may fail the authentication. If the SCEP template does not contain the Client Authentication field, correct the settings based on the video instruction.

In the registries, set the SCEP template name and disable EnforcePassword.
Find entries in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP, and set their values to the SCEP template name.
Registry modification takes effect only after the operating system is restarted.

Set EnforcePassword to 0.

Check the permission settings in the SCEP and OCSP templates. If the settings are incorrect, correct them based on the video instruction.


Check whether the SCEP and OCSP templates are issued. If SCEP and OCSP templates are not in the list, issue the templates based on the video instruction.

Choose to check whether OCSP is in working state. If not, delete ocsp_test and create it again based on the video instruction.

The properties of the revocation configuration and the random number and signature of the Agile Controller-Campus must have the relationship shown in the following figure:


