PortGuardNAC
  • Why PortGuard
  • Features
  • Use Cases
  • Pricing
  • Partners
  • Docs
  • Contact
🔐 Partner Login Book a Demo
Why PortGuard Features Use Cases Pricing Partners Docs Contact
Book a Demo →
// Admin Guide

5. Certificates & EAP-TLS

PortGuard v1.1.10 · ← Administrator’s Guide · Documentation

PortGuard ships a complete PKI for certificate-based 802.1X (EAP-TLS) — the equivalent of Microsoft AD CS, without the complexity.

Certificate Authority

Create the internal CA in one step (name, validity), or use Import Existing CA to bring in the certificate and key of a CA you already operate. Distribute the root certificate to clients as a trusted root (Intune, GPO or manually).

Client certificates (802.1X EAP-TLS)

  1. Choose the certificate type: Machine certificate (identity host/PCNAME, authenticates the computer itself — the port is authorized even before a user logs on) or User certificate (identity user@domain).
  2. Enter the identity — a password-protected PFX package is generated, ready to import.

Client Certificate Deployment — Intune

The deployment package bundles the root CA and the PFX with ready-made instructions for Microsoft Intune: target store Local Machine\Personal, EKU Client Authentication. Use it to push certificates to your fleet at scale.

Certificate Inventory

Every issued certificate with its expiry date. The Dashboard flags certificates that are expiring or expired.

Trusted CAs for EAP-TLS

Additional CAs accepted for client authentication — for example certificates issued by an existing corporate PKI or by Intune/NDES instead of the built-in CA.

HTTPS / TLS for the console

The web console certificate is managed separately under Settings → HTTPS: upload your own certificate/key or generate a self-signed one. See Administration.

Operational note: after replacing the EAP server certificate the RADIUS service needs a restart (a plain reload does not re-read TLS certificates). The console handles this for you when you apply the change.

← 4. Network Access Control
6. Security & Compliance →
PortGuardNAC
© 2026 Valerio Lollini / CrazyNet.
Why PortGuard Features Use Cases Pricing Partners Docs Status Support
Made with ♥ in Proudly built in Italy 🇮🇹
Privacy Policy· Cookie Policy· Terms of Service· EULA
CrazyNet · St Julian's, Malta · [email protected]
🍪 Cookies on this site

We only use essential technical cookies for authenticated areas — no tracking, no profiling, no third-party cookies. See our Cookie Policy.

PortGuardNAC AssistantAsk about features, setup, pricing
AI assistant — may be imperfect. For quotes or account issues, email [email protected].