Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass onboarding cert question

This thread has been viewed 1 times
  • 1.  ClearPass onboarding cert question

    Posted Jul 13, 2015 01:41 PM

    Hi forum,

     

    If I have a laptop that is used as a loaner for whoever needs it, does every user have to onboard or should it only be onboarded once?

    I guest a good question, is the onboard certificate has the username of the AD member or the Machine name?

     

    Thanks in advance,



  • 2.  RE: ClearPass onboarding cert question

    EMPLOYEE
    Posted Jul 13, 2015 01:47 PM

    If you are using user-based certificates, they are only available in the user context and each user would have to onboard.  If you are using machine or computer-based certificates, it only has to be done once.

     



  • 3.  RE: ClearPass onboarding cert question

    Posted Jul 13, 2015 01:49 PM

    If it is expected that only one user account or local account will be use to access the computer then it will only have to be onboard once using the account used initially to onboard the device



  • 4.  RE: ClearPass onboarding cert question

    Posted Jul 13, 2015 02:23 PM

    Actually it will be used by multiple AD members and I’m not sure if the good old Onboarding issues user certs or machine certs.



  • 5.  RE: ClearPass onboarding cert question

    EMPLOYEE
    Posted Jul 13, 2015 02:26 PM
    It's configurable in your provisioning settings.


    Thanks,
    Tim


  • 6.  RE: ClearPass onboarding cert question

    Posted Jul 13, 2015 02:28 PM

    Any idea which one is more secure? I guess user certs are more secure since the are tied to a user ad account.



  • 7.  RE: ClearPass onboarding cert question
    Best Answer

    EMPLOYEE
    Posted Jul 13, 2015 02:30 PM
    They're both secure. One is just more granular.


    Thanks,
    Tim