Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

SHA2 certificate upgradation in CPPM

This thread has been viewed 0 times
  • 1.  SHA2 certificate upgradation in CPPM

    Posted Sep 22, 2016 02:38 AM

    Hi,

       We are planning for a Server certificate migration from SHA 1 to SHA 256.

      I am totally new to this and have no idea about how to set this up,

    Can i get some good tips to do this activity.

    We currently have our Server running with SHA1.All clients are using SHA 1 for authentication.

     

    Thanks in advance.

     

    Regards



  • 2.  RE: SHA2 certificate upgradation in CPPM

    EMPLOYEE
    Posted Sep 22, 2016 05:02 AM

    Your question is very open-ended.  What encryption and authentication are your clients using?  

     

    Information on how to import a new server certificate on clearpass is here:  http://www.arubanetworks.com/techdocs/ClearPass/Aruba_CPPMOnlineHelp/index.htm#CPPM_UserGuide/Admin/ServerCertificateHelp.html



  • 3.  RE: SHA2 certificate upgradation in CPPM

    Posted Sep 22, 2016 11:52 PM

    Thanks Collin for sharing the info.

    For the missing info below are the points:

    * Currently the endpoits are using SHA1

    * Currently Client is using RADIUS authentication.

    * I am not aware how to find the encryption, ur guidenece will be helpful

     

    I have few other doubts also:

     

    * If we import SHA2 certificate in CPPM will the CPPM still uses SHA1 for endpoints not having SHA2 installed?

    * Also how to verify SHA2 migration is succesful and working succesfully

    * How to Roll back if my SHA2 migration fails in CPPM

     

    Thanks in advance

     

     

     



  • 4.  RE: SHA2 certificate upgradation in CPPM

    EMPLOYEE
    Posted Sep 23, 2016 05:01 AM

    In General:

     

    - The important thing is that your clients trust the new server certificate.  Whoever setup the system would know what mechanism they use to configure clients trusting the server certificate.

    - If you configure a SHA-2 certificate on CPPM, that is what clients will be using.

    - You should export the current ClearPass radius server certificate, so that you can import it later, just in case the import of the SHA-2 certificate does not work.

     

    Please contact Aruba TAC to work out the specifics of what you are trying to do, to ensure a successful migration.



  • 5.  RE: SHA2 certificate upgradation in CPPM

    EMPLOYEE
    Posted Sep 22, 2016 05:02 AM

    Your question is very open-ended.  What encryption and authentication are your clients using?  

     

    Information on how to import a new server certificate on clearpass is here:  http://www.arubanetworks.com/techdocs/ClearPass/Aruba_CPPMOnlineHelp/index.htm#CPPM_UserGuide/Admin/ServerCertificateHelp.html