PortGuard ships a complete PKI for certificate-based 802.1X (EAP-TLS) — the equivalent of Microsoft AD CS, without the complexity.
Create the internal CA in one step (name, validity), or use Import Existing CA to bring in the certificate and key of a CA you already operate. Distribute the root certificate to clients as a trusted root (Intune, GPO or manually).
host/PCNAME, authenticates the computer itself — the port is authorized even before a user logs on) or User certificate (identity user@domain).The deployment package bundles the root CA and the PFX with ready-made instructions for Microsoft Intune: target store Local Machine\Personal, EKU Client Authentication. Use it to push certificates to your fleet at scale.
Every issued certificate with its expiry date. The Dashboard flags certificates that are expiring or expired.
Additional CAs accepted for client authentication — for example certificates issued by an existing corporate PKI or by Intune/NDES instead of the built-in CA.
The web console certificate is managed separately under Settings → HTTPS: upload your own certificate/key or generate a self-signed one. See Administration.
Operational note: after replacing the EAP server certificate the RADIUS service needs a restart (a plain reload does not re-read TLS certificates). The console handles this for you when you apply the change.