Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboarding fails - can't determine trusted identity

This thread has been viewed 1 times
  • 1.  Onboarding fails - can't determine trusted identity

    Posted Feb 17, 2014 11:46 AM

    I have an issue onboarding one Mac.  The user reports that onboarding fails during profile installation.  The application log shows the following:

     

    Client: X.X.X.X:56921
    Script: /onboard/mdps_profile.php
    Function: NwaMdpsLogAndReportError
    Arguments: array (
    'error' => 1,
    'message' => 'Cannot determine trusted identity of certificate: /CN=XXXXXXXXXXXXXX',
    )

     

    The user has added the Onboarding Root CA to their cert store.

     

    Any thoughts?



  • 2.  RE: Onboarding fails - can't determine trusted identity

    Posted Feb 18, 2014 06:44 AM

     

     

    Can you verify if the device cert/cred were not revoked

     

     

    2014-02-18 06_42_55-Certificate Management.png



  • 3.  RE: Onboarding fails - can't determine trusted identity

    Posted Feb 21, 2014 04:48 PM

    The certificate was valid when the Mac tried onboarding first.  I deleted the certificate and the Mac had the same error message.

     

    The solution (if you can call it one) was to reinstall the OS on the Mac.  The user took it upon himself to do this, and is not my suggestion as it's pretty extreme.  The issue was definitely client side, but I wish I would've been able to nail it down.



  • 4.  RE: Onboarding fails - can't determine trusted identity

    Posted Apr 22, 2014 09:07 AM

    any one find fix for this? we having same issues with multiple iphones and ipad lately. Just started happening last week.

     



  • 5.  RE: Onboarding fails - can't determine trusted identity

    Posted Apr 29, 2014 03:57 PM

    Hi,

     

    I can confirm that we are seeing this issue as well.

    Something new, I was actually trying to test something different.

     

    Tested on iPad Mini running iOS 7.0.6

     

    CPPM 6.2.2



  • 6.  RE: Onboarding fails - can't determine trusted identity

    EMPLOYEE
    Posted Apr 29, 2014 07:11 PM


  • 7.  RE: Onboarding fails - can't determine trusted identity

    Posted Apr 30, 2014 10:58 AM

    hey tarnold,

     

    thank you sir.

     

    We are a few patches behind so I need to get our CPPM up to date and then load that patch.

     

    We are running 6.2.2 and are waiting to install patch 6.2.6.

    The iOS patch appears to be separate. I will download and install once we can patch our system first.

     

    Cheers