Intermediate-Trust certificate issues

Hector Rodriguez via Freeradius-Users <[email protected]> Fri, 1 May 2026 18:35:10 +0000
Newsgroups gmane.comp.freeradius.user
Message-ID <BL1PR01MB7675C9C566D3E748384EA837F3322@BL1PR01MB7675.prod.exchangelabs.com>
--===============0218681468817070066==
Content-Language: en-US
Content-Type: multipart/related;
	boundary="_004_BL1PR01MB7675C9C566D3E748384EA837F3322BL1PR01MB7675prod_";
	type="multipart/alternative"

--_004_BL1PR01MB7675C9C566D3E748384EA837F3322BL1PR01MB7675prod_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hello,

  I hope everyone is well. Currently I have implemented Free Radius in a te=
st environment with EAP-TLS mode enabled. My environment currently has a tw=
o tier PKI (CA Root and Ca Issuer within the Intune Microsoft Cloud PKI env=
ironment) . Our Free Radius server is configured to have an SSL from the CA=
 server installed within my Free Radius Server, which is generated by the C=
A config. Our Root CA and Issuer CA certificates have been imported from In=
tune, and converted from Cer to PEM/CRT file formats, and the EAP config fi=
le has been edited to point to a bundled (full chain ) Issuer CA cert. The =
server's certificate store has been updated to trust the Microsoft CA and I=
ssuer CA for our environment . I have created a configuration profile withi=
n Intune to grant machines (in my case, just a test machine) to install bot=
h CA ROOT and Issuer certs to their prespective certificate store.  Public =
certs are owned by the freerad user and currently have the 755 permissions
   Another thing to note is that we are currently using a Unifi switch and =
we have set the controller profile to authenticate with Radius. I have been=
 going a bit insane trying to figure out why the Free Radius server is not =
trusting my intermediate certificate when I have clearly followed the appro=
priate instructions. No matter what I do the intermediate cert is not trust=
ed. Authentication only occurs when I set:reject_unknown_intermediate_ca  t=
o No. I have been notciing that other users have a similar issue, with PKI'=
s related to Microsoft Cloud PKI. Do you thing there will be a fix. Is ther=
e anything that I can do for this issue ? Although it seems unsafe, do you =
think it would be Ok, to  set reject_unknown_intermediate_ca =3Dno  ?

Piece of my log errors:

Certificate chain - 1 intermediate CA cert(s) untrusted
To forbid these certificates see 'reject_unknown_intermediate_ca'
(TLS) untrusted certificate with depth [1] subject name /C=3DUS/ST=3Dtest/L=
=3Dtestn/OU=3DInformation Technology/O=3Dtest-site Inc/CN=3DTest-Issuing-Cl=
oud-CA1
(TLS) untrusted certificate with depth [0] subject name /CN=3DAP-tesetmachi=
ne
tls: There are untrusted certificates in the certificate chain.  Rejecting.
(13) eap_tls: (TLS) TLS - send TLS 1.3 Alert, fatal internal_error
(13) eap_tls: ERROR: (TLS) TLS - Alert write:fatal:internal error
(13) eap_tls: ERROR: (TLS) TLS - Server : Error in error
(13) eap_tls: ERROR: (TLS) Failed reading from OpenSSL: error:0A000086:SSL =
routines::certificate verify failed
(13) eap_tls: ERROR: (TLS) System call (I/O) error (-1)
(13) eap_tls: ERROR: (TLS) EAP Receive handshake failed during operation
(13) eap_tls: ERROR: [eaptls process] =3D fail
(13) eap: ERROR: Failed continuing EAP TLS (13) session.  EAP sub-module fa=
iled
(13) eap: Sending EAP Failure (code 4) ID 10 length 4
(13) eap: Failed in EAP select
(13)     [eap] =3D invalid
(13)   } # authenticate =3D invalid
(13) Failed to authenticate the user
(13) Using Post-Auth-Type Reject
(13) # Executing group from file /etc/freeradius/3.0/sites-enabled/default
(13)   Post-Auth-Type REJECT {
(13) attr_filter.access_reject: EXPAND %{User-Name}


Thank you !





















[cid:59049752-c8e4-4c9b-8b16-c6e2ede5715f]<https://outlook.office.com/bookw=
ithme/user/[email protected]?anonymous&ismsaljs=
authenabled&ep=3DbwmEmailSignature>
Book time to meet with me<https://outlook.office.com/bookwithme/user/af4e41=
[email protected]?anonymous&ismsaljsauthenabled&ep=3D=
bwmEmailSignature>
-- CONFIDENTIALITY NOTICE: This email and any files transmitted with it are=
 confidential and are intended solely for the use of the individual or enti=
ty to which they are addressed. This communication may contain material pro=
tected by HIPAA legislation (45 CFR, Parts 160 & 164) or by 42 CFR Part 2. =
If you are not the intended recipient, be advised that you have received th=
is email in error and that any use, dissemination, forwarding, printing or =
copying of this email is strictly prohibited. If you have received this ema=
il in error, please notify the sender by reply email and destroy all copies=
 of the original message. =AD=AD

--_004_BL1PR01MB7675C9C566D3E748384EA837F3322BL1PR01MB7675prod_
Content-Type: image/png; name="Outlook-x0wv523f.png"
Content-Description: Outlook-x0wv523f.png
Content-Disposition: inline; filename="Outlook-x0wv523f.png"; size=528;
	creation-date="Fri, 01 May 2026 18:35:10 GMT";
	modification-date="Fri, 01 May 2026 18:35:10 GMT"
Content-ID: <59049752-c8e4-4c9b-8b16-c6e2ede5715f>
Content-Transfer-Encoding: base64

iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAAAXNSR0IArs4c6QAAAcpJREFUOE9j
ZAABr6aJDHqhuQwMDIxgPrHg19d3DLP91Bk+P3sD08IIN2x1hjPDy7NXiDWL4T8nM0NA33wGWRMP
hg5NJgYGhv8gvYwMFdf/MYAMu3twP9GGISssv/qLYVdzMsP5FYthBv5nmO2pyfDzzVuyDEw/eJ3h
xNyJDEenNSMMJMskJE2Hp9YxHJ2CZOBUM1GGz5/hAUuS+UVnXjOcXDCJygbOm4TqZUpcGDJjJcPz
S1eoYyAvrzDD58/vGRgY/iHSYcX1/wykupBXWpghe89reEbY0RjNcGHFMkQsk2pgwYkXDBz84iiR
16EJzmWghE26C8uv/mZgZGJBM5AZ5HXyDPRo7GMwCCuEG/jj40uGCRYS5LsQpNM6q4TBOLqE4emF
gwxrs8NRI2WynSTD19cvSErQOBQzMhSdecvw8vophqWxngQNBCWTrBMvMMIPpnF7dQQjA6+UCEP2
3tcM//7+Zvjx8QNOQydZizFk7bvNwCepgs9iWIHKyGAYEcPALaQEUQwq3mBplQmi5siUBoa0bRcZ
hBT18Bj4n7QSWlhGmiF19xOcBh6aVEyagSCTQEEUNf8Ag6CcFjyn/Pz8hmF9cQjDg8MHAaiKxp0e
iZJ4AAAAAElFTkSuQmCC

--_004_BL1PR01MB7675C9C566D3E748384EA837F3322BL1PR01MB7675prod_--

--===============0218681468817070066==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

--===============0218681468817070066==--