Troubleshooting Server Certificate Validation for RADIUS
Overview
When a RADIUS server uses a self-signed certificate or a certificate issued by an untrusted Certificate Authority (CA), most clients reject the connection because they cannot validate the server's identity. For troubleshooting purposes, you can disable server certificate validation on one or more clients to allow those clients to connect regardless of the certificate in use.
Note: Disabling server certificate validation introduces security risks. Use a trusted certificate as the permanent resolution.
Troubleshooting server certificate validation
Troubleshooting steps
The following steps describe how to disable server certificate validation on supported client operating systems for troubleshooting purposes.
Windows 7/8
- Navigate to Control Panel > Network and Sharing Center > Manage wireless networks.
- If the user sees different options, they should switch from View by Categories to Small icons or Large icons.
- Right-click the interface or network in question and select Properties.
- On the Security tab, click Settings.
- At the top of the Settings window, uncheck the box labeled Validate server certificate.
Windows 10/11
- Navigate to Control Panel > Network and Sharing Center > Change adapter settings.
- If the user sees different options, they should switch from View by Categories to Small icons or Large icons.
- Double-click the interface or network in question and select Properties.
- On the Authentication tab, click Settings.
- At the top of the Settings window, uncheck the box labeled Verify the server's identity by validating the certificate.
MacOS
On macOS, authentication can take up to 10 seconds to complete. This delay occurs when the RADIUS certificate, or any certificate in the chain, is configured for Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP) checks. Refer to Apple Support for more details.

