Security

last person joined: 12 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

SSL Certificate Expired, Make Windows got problem

This thread has been viewed 5 times
  • 1.  SSL Certificate Expired, Make Windows got problem

    Posted Aug 21, 2017 03:42 AM

    Hi Airhead,

    i got problem with windows user, i used 802.1x authentication windows user got problem with autentication to connect network aruba.

     

    and i reach Aruba TAC and see the problem with SSL certificate expired, so why just windows user got problem but, the user android, ios, mac, linux reach the network aruba.

     

    what the solution beside renewal the SSL certificate ?

    can used the self certificate form windows server or linux ?

     

    Regards,

    Ratih Apsari



  • 2.  RE: SSL Certificate Expired, Make Windows got problem

    MVP EXPERT
    Posted Aug 21, 2017 04:09 AM

    We'll need to understand a bit more information about your deployment but if I take a guess I suspect this is the certificate used for machine authentication. The mobile devices I suspect aren't doing machine authentication so there for not having issues. 

     

    If you take a look at the certificate, show is the Trusted CA? They will need to generate a new certificate for you if the existing one has expired. 

     

    If you are using the Aruba certificate then follow the below:

     

    https://community.arubanetworks.com/t5/Controller-less-WLANs/ArubaOS-Default-Certificate-Revocation-FAQ-Instant/ta-p/275814



  • 3.  RE: SSL Certificate Expired, Make Windows got problem
    Best Answer

    EMPLOYEE
    Posted Aug 21, 2017 04:12 AM

    That is because all of those other operating systems will allow you to operate with an expired certificate.  Windows is a system used in the enterprise and it has protection to ensure that you are not compromised because of an expired certificate.  

     

    If someone puts up an SSID that looks exactly like yours with an expired certificate, they could easily allow your users to connect to the fake SSID and collect all of their usernames and passwords.

     

    When your Radius Server was built, a user generated a server certificate.  You need to generate another certificate that is trusted by your Windows Devices.