Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Configuring Auto/Single Sign On on CPPM

This thread has been viewed 5 times
  • 1.  Configuring Auto/Single Sign On on CPPM

    Posted Sep 04, 2015 08:30 AM

    Hi All

     

    Hopefully someone can help me as I am really struggling

     

    We are trying to get CPPM to authenticate users to salesforce and Box using OKTA. I have followed the SAML config guide but, if I'm honest, I don't get it!

     

    We have set up clearpass as an endpoint in Okta and then tried various things like putting the Okta URL in the SSO profile on the controller, creating SSO services in CPPM etc. But when users connect and go to the OKTA sign in page, nothing happens. I would expect to at least see an auth attempt in Access Tracker but nothing.

     

    Any help would be gratefully accepted.



  • 2.  RE: Configuring Auto/Single Sign On on CPPM

    Posted Sep 13, 2015 11:00 AM

    could you provide some more detail on how a user starts this process for example?

     

    have you been working with this:

    http://www.arubanetworks.com/techdocs/ArubaOS_64x_WebHelp/Content/ArubaFrameStyles/802.1x/Applicaltion%20SSO%20with%20L2.htm

     

    or not at all?



  • 3.  RE: Configuring Auto/Single Sign On on CPPM

    Posted Sep 14, 2015 06:39 AM

    Hi

     

    We had a lot of issues with this and are still not quite there. When the user has completed dot1X auth, they could go to their Okta sign in page and should have been authenticated properly. However that was failing as apparently Okta requires an email address rather than an AD username. We are working with the end user's Okta expert currently to see how we can get round this (although, with TAC help, we can authenticate our users using their email address instead of AD username).

     

    We believe we have the Clearpass/mobility controller config correct though.