Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cert for Captive portal with internal DNS

This thread has been viewed 4 times
  • 1.  Cert for Captive portal with internal DNS

    Posted Mar 13, 2014 09:43 AM

    hey all,

     

    what is the best way to go about generating a cert for my captive portal on my controller that only has an internal domain name?

     

    Thanks,

     

    rafael



  • 2.  RE: Cert for Captive portal with internal DNS

    EMPLOYEE
    Posted Mar 13, 2014 12:58 PM
    Whatever name the client devices will use to access the controller should
    be what you use for the CN of the cert.


  • 3.  RE: Cert for Captive portal with internal DNS

    Posted Mar 13, 2014 01:06 PM

    ok, and what name will clients use in terms of captive portal?



  • 4.  RE: Cert for Captive portal with internal DNS

    EMPLOYEE
    Posted Mar 13, 2014 01:18 PM

    The captive portal will use the CN of the certificate that you have selected for the controller. If you use the DNS name of your controller, you can use the cert for both Mgmt UI and captive portal without getting SSL errors.



  • 5.  RE: Cert for Captive portal with internal DNS

    Posted Mar 13, 2014 01:30 PM

    Right, and there in lies the problem (pgh-local.mycompany.int).  We have an internal domain that is .int and since .int is actually a usable external DNS suffix I can't get a cert from a public CA or whatever Thawte and Go Daddy are...

     

    rafael



  • 6.  RE: Cert for Captive portal with internal DNS

    EMPLOYEE
    Posted Mar 13, 2014 01:33 PM
    Do you have a public facing domain name though? You could always do a
    generic wireless.domain.com just for the captive portal. The DNS name
    doesn't have to actually exist.


  • 7.  RE: Cert for Captive portal with internal DNS

    Posted Mar 13, 2014 01:38 PM

    Really? hmmm, how does that work?  

     

    thanks,

     

    rafael



  • 8.  RE: Cert for Captive portal with internal DNS

    EMPLOYEE
    Posted Mar 13, 2014 01:40 PM
    It's part of the captive portal redirect process.


  • 9.  RE: Cert for Captive portal with internal DNS

    Posted Mar 13, 2014 01:41 PM

    "Do you have a public facing domain name though? You could always do a
    generic wireless.domain.com just for the captive portal. The DNS name
    doesn't have to actually exist."

     

    i mean if I use wireless.mydomain.com don't I need a corresponding "a" record in DNS so the client can find the captive portal?

     

    rafael



  • 10.  RE: Cert for Captive portal with internal DNS

    EMPLOYEE
    Posted Mar 13, 2014 01:45 PM
    No. The controller will intercept traffic and dst-nat it to the controller.
    The client never directly navigates to the CP.


  • 11.  RE: Cert for Captive portal with internal DNS

    Posted Mar 13, 2014 01:47 PM

    Achah! that makes sence.  

     

    Thanks,

     

    rafael