Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

IOS Profile installation failed with OnBoard

This thread has been viewed 3 times
  • 1.  IOS Profile installation failed with OnBoard

    EMPLOYEE
    Posted Jun 08, 2018 04:40 PM

    Hello,

     

    i am running 6.7 version of CPPM for a customer POC. since it's a POC we don't have any public certs. 

    I created the Onboard CA in clearpass and used that to sign the radius certificate for Clearpass. Device enrollment for IOS is failing with error message " Profile installation failed",the server cartifcate for "https"//xxxx/guest/mdps_profile.php/xxxxxxxx is invalid.

     

    i followed some of the previous community posts and disabled HTTPS both in  ClearPass and Controller captive portal profile.

    also checked NO, for web server certifcate validation. 

     

    is there anything else i can do to get this working for POC? 

     

    thanks 

    Kandhla

     



  • 2.  RE: IOS Profile installation failed with OnBoard

    EMPLOYEE
    Posted Jun 09, 2018 02:32 AM
    You need to have a public HTTPS certificate. This is Apple's requirement.


  • 3.  RE: IOS Profile installation failed with OnBoard

    Posted Jun 09, 2018 07:01 AM
    Hi, which OS (windows 7,10, macOS)?


  • 4.  RE: IOS Profile installation failed with OnBoard

    Posted Jun 09, 2018 07:01 AM
    Hi, which OS (windows 7,10, macOS)?


  • 5.  RE: IOS Profile installation failed with OnBoard

    Posted Jun 09, 2018 07:03 AM
    You could also create a temporary public certificate via verisign I think... they have a trial version if I recall


  • 6.  RE: IOS Profile installation failed with OnBoard

    Posted Jun 09, 2018 07:03 AM
    You could also create a temporary public certificate via verisign I think... they have a trial version if I recall


  • 7.  RE: IOS Profile installation failed with OnBoard

    MVP EXPERT
    Posted Jun 09, 2018 11:43 AM
    You can use a lets encrypt certificate for free for 90-days. Comodo also have trail certs..... or you buy some... is not that expensive 😉


  • 8.  RE: IOS Profile installation failed with OnBoard

    EMPLOYEE
    Posted Oct 14, 2018 09:41 AM

    Hi Kandhla,

     

    Have you found your solution for this?  I am having the same issue.  Hoping for your reply.

     

     



  • 9.  RE: IOS Profile installation failed with OnBoard

    EMPLOYEE
    Posted Oct 14, 2018 11:05 AM

    Since I do not have public HTTPS certificate and I am using IOS device, I tried to change from https to http in the captive portal profile and it works.  



  • 10.  RE: IOS Profile installation failed with OnBoard

    EMPLOYEE
    Posted Oct 14, 2018 11:07 AM
    You need to have a public certificate for HTTPS for ClearPass. You should not be running anything over HTTP.


  • 11.  RE: IOS Profile installation failed with OnBoard

    EMPLOYEE
    Posted Oct 14, 2018 11:17 AM

    Hi Tim,

     

    Noted and thanks for the advise.  This is for my internal lab testing.