- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
07-12-2017 03:42 PM
Hi guys,
I have read and tested the guest sponsor approval feature in ClearPass. It seems a nice feature but I see a shortcoming. When the client enter their name and email address in the registration window and click on Register, these parameters along others are sent to the sponsor for approval, but the sponsor can't be sure the client is who he says it is, and the sponsor could approve an account for a not desired person. Is there a way to authenticate the client?
Regards,
Julián
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
07-12-2017 03:48 PM
I don't think this is intended to be a high security mechanism; I think it is to provide some protection from totally open guest access. The sponsor does not have to answer if he does not know the user, or does not know the email address of the user.
Colin Joseph
Aruba Customer Engineering
Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Guest Sponsor Approval
Re: Guest Sponsor Approval
07-12-2017 03:56 PM
That is what I refer to, a bad client could enter an email address of a known user to the sponsor (supposing he knows that email), but the client isn't actually that user. The sponsor would approve and give access to the bad client.
Regards,
Julián
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
07-12-2017 03:59 PM
Yes. The sponsor is usually expecting the guest. There's nothing really you can do about this. Not a technical issue. It's just guest access.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Guest Sponsor Approval
Re: Guest Sponsor Approval
07-13-2017 06:59 AM
Hi Colin and Tim,
Yeah, I totally agree with both that the feature is intended for give some protection from totally open guest access and is not a technical issue, just wondering if there is a way to authenticate the user. It makes sense.
On the other hand, just a little question, do you know where I can find the guest user repository in ClearPass where all the guest created accounts are? I can't find this page.
Regards,
Julián
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Guest Sponsor Approval
Re: Guest Sponsor Approval
07-13-2017 07:20 AM
Guest > Guest > Manage Accounts
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Guest Sponsor Approval
Re: Guest Sponsor Approval
07-13-2017 07:39 AM
Pretty simple, many thanks!
Regards,
Julián
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Guest Sponsor Approval
Re: Guest Sponsor Approval
07-14-2017 05:11 AM
in my opinion, i believe that same logic same goes to email address signups because it is meant for public use. the only thing mail domains like Yahoo can do is to make sure that there are no bots or AI registering and that is thru Captcha or sms verifications.
same goes to your clearpass guest which uses email or sms for verification
am i right?
let me know your thoughts
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Guest Sponsor Approval
Re: Guest Sponsor Approval
07-14-2017 06:33 AM
Hi harveyysip,
Yes, the same would apply to the self-registration flavor, the visitor can enter an invalid email address. ClearPass also have the option to include Captcha to avoid robots.
Regards,
Julián
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator