Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboarding BYOD with firewall certificate

This thread has been viewed 1 times
  • 1.  Onboarding BYOD with firewall certificate

    Posted Jun 20, 2018 11:38 AM

    Hi guys,

     

    I have a customer which wants to onboard BYOD devices, in addition to install the required certificates on them for onboarding and using them in the corporate network, he wants to install the firewall certificate (.cer) on them in order to use the deep inspection feature on the firewall. Can Clearpass install the firewall certificate on them?

     

    Regards,

    Julián



  • 2.  RE: Onboarding BYOD with firewall certificate

    EMPLOYEE
    Posted Jun 20, 2018 11:42 AM
    No, there are OS limitations that prevent automatically configuring TLS decryption certificates for privacy reasons.


  • 3.  RE: Onboarding BYOD with firewall certificate

    Posted Jun 20, 2018 11:50 AM

    Hi Tim,

     

    So that limitation is on ClearPass?

     

    Regards,

    Julián



  • 4.  RE: Onboarding BYOD with firewall certificate

    EMPLOYEE
    Posted Jun 20, 2018 11:52 AM

    No, as mentioned, they are OS restrictions due to privacy concerns.



  • 5.  RE: Onboarding BYOD with firewall certificate

    Posted Jun 20, 2018 11:54 AM

    Hi Tim,

     

    But when you say OS restrictions what do you mean exactly? ArubaOS firmware? The mobile phone OS?

     

    Regards,

    Julián



  • 6.  RE: Onboarding BYOD with firewall certificate

    Posted Jun 20, 2018 04:15 PM

    Hi,

     

    In the following thread jima_uk also wanted to use firewall certificates for deep inspection. Isn't the same?

     

    We just need a method to "force" the certificate onto BYOD type devices to ensure the web filter decryption works seamlessly. At the moment without the certificate the end client gets a trust warning and on a lot of smart phones that effectively makes it looks like they have no internet conneciton, especially to less savy end users. The devices are not on our domain and also not managed by an MDM so searching for other solutions.

     

    http://community.arubanetworks.com/t5/Security/Deploying-additional-certificates/td-p/269180

     

    Regards,

    Julián



  • 7.  RE: Onboarding BYOD with firewall certificate

    EMPLOYEE
    Posted Jun 20, 2018 04:18 PM
    No, this no longer possible due to device restrictions.


  • 8.  RE: Onboarding BYOD with firewall certificate

    Posted Jun 20, 2018 04:22 PM

    Hi Tim,

     

    Ah, then you mean before was possible but not now due to the phones restrictions? So if ClearPass wants to install these certificates on the phones will fail?

     

    Regards,

    Julián



  • 9.  RE: Onboarding BYOD with firewall certificate

    EMPLOYEE
    Posted Jun 20, 2018 04:34 PM
    It has nothing to do with the installation. Many devices will not implicitly trust the CA.