Specifications
802.1x Configuration 213
Chapter 10
certificate. The client’s certificate is then verified against the CA certificate of
the authority which issued it (Clients do not have to validate the Server
certificate in order for 802.1x to function).
Server Certificates and Certificate Verification
Similar to client certificates, a server has a certificate which authenticates its
identity. The first time a client associates with a server, or the first time after
the server’s certificate has expired or been revoked, the client makes a request
for the server’s authentication certificate. The server’s certificate is then
verified against the CA certificate of the authority which issued it.
Certification Authority (CA) Certificates
A certification authority issues authentication certificates to both servers and
clients. The only way to assure that a certificate issued to a client or server is
valid is to examine the digital signature. This is done by comparing it to the
digital signature on the issuing certification authority’s CA certificate.
Therefore, to complete the authentication process for either a server or client
the parties must have both the CA and the client/server certificate.