Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Radius certificate & OnBoard Intermediate CA

This thread has been viewed 5 times
  • 1.  ClearPass Radius certificate & OnBoard Intermediate CA

    Posted Aug 15, 2018 12:02 PM

    Our CPPM Radius certificate is getting ready to expire so we're working on renewing it. The question that I've run into, though, is that the current certificate is signed by the OnBoard intermediate CA, in turn signed by the AD CA. Is there a particular need for the Radius cert to be signed by the internal intermediate CA, or would it be fine to use a cert signed directly by the AD CA?



  • 2.  RE: ClearPass Radius certificate & OnBoard Intermediate CA

    EMPLOYEE
    Posted Aug 15, 2018 12:04 PM
    The EAP server certificate must be trusted by the clients. How are the supplicants configured?


  • 3.  RE: ClearPass Radius certificate & OnBoard Intermediate CA

    Posted Aug 15, 2018 12:41 PM

    I'll have to double check, but I believe at the moment it's basically Windows default. I'm working in the direction of enforced dot1x via wire and wireless, and would like to get group policies defined for the windows clients to make it transparent to enterprise devices. I'm testing with my machine, and do periodically get the 'Windows can't verify the server's identity. If you expect to find %1 in this location..." message.



  • 4.  RE: ClearPass Radius certificate & OnBoard Intermediate CA
    Best Answer

    EMPLOYEE
    Posted Aug 15, 2018 12:52 PM
    The EAP server certificate can be issued from wherever you choose, as long as the supplicants are appropriately configured.


  • 5.  RE: ClearPass Radius certificate & OnBoard Intermediate CA

    Posted Aug 15, 2018 01:04 PM

    Thank you for that. I just wanted to verify there wasn't something I was missing. I've been bit by changing radius certificates once before and wanted to make sure there wasn't a gotcha I was missing with OnBoard.