Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM RADIUS server certificate

This thread has been viewed 7 times
  • 1.  CPPM RADIUS server certificate

    Posted Jul 07, 2018 02:05 AM

    We currently have a cluster of one Pub/Sub CPPM.  Both have same Internal RADIUS server certificate installed & currently used for a SSID(EAP-TLS  authentication). New plan is to deploy one more SSID and use EAP-TLS aswell however these 2 SSID/Users are in completely different environment.  

    My question is can I install one more internal RADIUS server certificate on pub/sub and use it for this new SSID? So two SSID will use different internal cert to authenticate? Only reason I want to do is not to Mix different envirnoment using same cert to authenticate. 



  • 2.  RE: CPPM RADIUS server certificate

    MVP EXPERT
    Posted Jul 07, 2018 04:44 AM
    You can only deploy one radius and one https certificate and must be the same at the publisher and subsciber node.

    The client check the radius server certificate against his ca trustlist, to trust the clearpass server

    Clearpass check the machine and or user certificate against his ca trustlist to trust the machine or user.

    If you look in clearpass accesstracker you can see that an eap-tls authentication have just a ieft-radius-username with the value “username” or “machine name” that will authenticated against your authentication server.

    So there is no issue. You can make roles and enforcementprolfiles based on for example “authentication source equals “ad1”. Or make roles bases on ad groupmembeship OU.

    Hope this help you!


  • 3.  RE: CPPM RADIUS server certificate

    EMPLOYEE
    Posted Jul 07, 2018 08:41 AM
    You can use a per-service EAP server certificate but it really needs to be planned out well. You need to scope the service on something like SSID or username format.

    Also, keep in mind that the server identity has nothing to do with the client certificate trust chain. Said differently, you can use the same EAP server cert with different client cert issuers.


  • 4.  RE: CPPM RADIUS server certificate

    MVP EXPERT
    Posted Jul 07, 2018 11:35 AM
    Tim is also right 👍