Security

last person joined: 14 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass and Onboard CA for provisioning IOS devices

This thread has been viewed 4 times
  • 1.  ClearPass and Onboard CA for provisioning IOS devices

    Posted Feb 17, 2017 12:13 PM
    Hi All, I have some confusion with the CA setup required for using OnBoard to provision IOS devices to an SSID. I have a wildcard cert from entrust, can I import it for the Root CA on ClearPass or do I need to purchase a new certificate and file the CSR ? The documentation is not clear. N


  • 2.  RE: ClearPass and Onboard CA for provisioning IOS devices

    EMPLOYEE
    Posted Feb 17, 2017 01:09 PM
    You should not use a wildcard certificate as the RADIUS / EAP certificate.
    You can, however, use it as the web server certificate.


  • 3.  RE: ClearPass and Onboard CA for provisioning IOS devices

    EMPLOYEE
    Posted Feb 17, 2017 01:09 PM
    You should not use a wildcard certificate as the RADIUS / EAP certificate.
    You can, however, use it as the web server certificate.


  • 4.  RE: ClearPass and Onboard CA for provisioning IOS devices
    Best Answer

    EMPLOYEE
    Posted Feb 18, 2017 11:47 AM

    You cannot use your public Entrust certificate as the OnBoard CA, as it is not allowed to sign other certificates, it can only be used to authenticate the ClearPass server to clients. And as Tim said, don't use a wildcard as your RADIUS certificate.

     

    Regarding documentation, for selecting the right certificates I'd suggest that you check out the ClearPass Certificates 101 Technote (that can be found here: https://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/EntryId/7961/Default.aspx). There is quite some content about what choices you have to pick the right certificates in your Onboard scenario (you will likely end up initializing a new Onboard CA as root, which is quite easy to do)

     



  • 5.  RE: ClearPass and Onboard CA for provisioning IOS devices

    Posted Feb 22, 2017 12:08 PM
    Thanks, Root CA for byod devices, public cert for RADIUS works well. N