Security

last person joined: 16 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Certificate for Captive Portal

This thread has been viewed 12 times
  • 1.  Certificate for Captive Portal

    Posted Dec 11, 2013 09:24 AM

    I have 3 controllers (1 Master and 2 Locals). Do I need to have a different certificate for each controller for Captive Portal or do I need just one?



  • 2.  RE: Certificate for Captive Portal

    Posted Dec 11, 2013 09:29 AM

    You need one for each



  • 3.  RE: Certificate for Captive Portal

    Posted Dec 11, 2013 09:39 AM

    Thanks for the response. Do I need to have the CSR for the controller name or the SSID (Guest)?



  • 4.  RE: Certificate for Captive Portal

    Posted Dec 11, 2013 09:43 AM


    Controller



  • 5.  RE: Certificate for Captive Portal

    EMPLOYEE
    Posted Dec 11, 2013 10:16 AM
    If you do the CSR on server where you can export the private key (IIS or
    openssl, you could use the same cert on all 3. You could do something
    generic like wireless. domain.com


  • 6.  RE: Certificate for Captive Portal

    EMPLOYEE
    Posted Dec 11, 2013 10:21 AM

    @jcameron wrote:

    I have 3 controllers (1 Master and 2 Locals). Do I need to have a different certificate for each controller for Captive Portal or do I need just one?


    You have a choice:

     

    1.  One Certificate for each Controller, each with its own Subject as its FQDN or

    2.  A Single Certificate, that can be installed on all of your controllers, but FQDNs for your controllers  entered in the SAN or Subject Alternate Name field on the CSR form at your Certificate Authority:  http://en.wikipedia.org/wiki/SubjectAltName

     

    Please know that

     

    - the CSR form for the controller does not have a Subject Alternate name field, so you cannot generate it there for option (2).  You would need to generate the CSR using the Certificate Authority's form...

    - If you Generate a CSR from a controller, it will stay in there, so you cannot generate another unless you import a corresponding certificate

    - Certificate Authorities charge more for additional subject alternate names, but not as much as an entire certificate, but shop around.

     

     



  • 7.  RE: Certificate for Captive Portal

    Posted Dec 11, 2013 10:37 AM

    Thanks, Colin. I created certs with the FQDN of each controller as the Common Name. Is this right?



  • 8.  RE: Certificate for Captive Portal

    EMPLOYEE
    Posted Dec 11, 2013 11:12 AM

    Correct.

     



  • 9.  RE: Certificate for Captive Portal

    Posted Dec 12, 2013 07:36 AM

    I got the certs they are in p7b format. When I upload them onto the controller then go Management -> General and try to change the cert for Captive Portal it does not show up.



  • 10.  RE: Certificate for Captive Portal

    EMPLOYEE
    Posted Dec 12, 2013 08:58 AM

    Did you upload it as a "server cert"?

     

    Also, make sure the root CA that signed the cert is uploaded as a "Trusted CA".



  • 11.  RE: Certificate for Captive Portal

    Posted Dec 12, 2013 09:02 AM

    I only got one cert file. When I view the file I see 3 certs inside. Do I need to export each cert from the file?

    I am used to a server where it took the file as it is.



  • 12.  RE: Certificate for Captive Portal

    EMPLOYEE
    Posted Dec 12, 2013 09:08 AM

    I believe when uploading to the controller, you will need separate files for the server cert and root CA. You should be able to open the file as plain text and split them into different files.

     

    Then upload the Root CA first, then the server cert.

     

    internalca.PNG

     

    Did you do the CSR on the controller or another server?



  • 13.  RE: Certificate for Captive Portal

    Posted Dec 12, 2013 09:12 AM

    When I open as a text file, it only shows the type cert in the path .

     

    I made the CSR on the controller.