Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Certificate on CPPM

This thread has been viewed 2 times
  • 1.  Certificate on CPPM

    Posted Sep 11, 2013 05:09 AM

    Hi All,

     

    We are performing EAP-TLS authetication.

     

    Enterprise Active directory is going to issue certificates to domain computer and domain users and CPPM just authenticates.

     

    We need clarification that do we need to upload any certificate on CPPM for EAP-TLS if the root CA is from AD.

     

     

    Regards,

    Nithin Kumar C V



  • 2.  RE: Certificate on CPPM

    EMPLOYEE
    Posted Sep 11, 2013 07:47 AM

    @Nithin wrote:

    Hi All,

     

    We are performing EAP-TLS authetication.

     

    Enterprise Active directory is going to issue certificates to domain computer and domain users and CPPM just authenticates.

     

    We need clarification that do we need to upload any certificate on CPPM for EAP-TLS if the root CA is from AD.

     

     

    Regards,

    Nithin Kumar C V


    You do need to upload the CA's root certificate to CPPM's trusted root authority to authenticate EAP-TLS users.  You will also have to issue CPPM a server certificate that your EAP-TLS clients trust.



  • 3.  RE: Certificate on CPPM

    Posted Sep 11, 2013 08:23 AM

    You do need to upload the CA's root certificate to CPPM's trusted root authority to authenticate EAP-TLS users.

     

    -------You mean to say that we have to import the Root CA to CPPM at Server certificate tab.

     

    You will also have to issue CPPM a server certificate that your EAP-TLS clients trust.

     

    ------- how to do this ?

     


    Do u have any document or screen shot.

     

    Regards,


    Nithin Kumar C V



  • 4.  RE: Certificate on CPPM

    EMPLOYEE
    Posted Sep 11, 2013 09:08 AM

    The root cert (and entire trust chain ideally) should be in CPPM's trusted cert list.  That is found in the Adminitration area.

     

    CPPM itself needs a server certificate issued BY YOUR CA.  This is so when the client authenticates, the server side of the trust is verified by the client as the same CA ultimately issued the cert.