Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

TLS with AD and CPPM in between

This thread has been viewed 3 times
  • 1.  TLS with AD and CPPM in between

    Posted Jan 22, 2017 06:41 PM

    Hi Forum,

     

    Users have a cert issued by AD and used to authenticates directly to AD with aruba controller. I installed CPPM in between the users and AD for added profiling and BYOD capabilities of ClearPass. My ClearPass has a valid RADIUS cert issued for the root CA, the root CA cert and the intermediate CA cert are in CPPM's trusted list. ClearPass cert, Root CA, intermediate CA certs are all manually installed/trusted on client devices (GPO push). PEAP is working fine but not TLS.

    I get an error saying TLS handshake failed and error unknown CA by client.

    The only thing that I need to ask about is:

    there is a firewall between the clients and CPPM and that firewall has a cert for SSL decryption and some advance L7 features. Does the client need to trust that cert as well?! 

     

    Thanks,



  • 2.  RE: TLS with AD and CPPM in between

    EMPLOYEE
    Posted Jan 22, 2017 06:47 PM

    The client needs to trust the ClearPass server cert and/or the CA that issued the Server Cert



  • 3.  RE: TLS with AD and CPPM in between

    Posted Jan 22, 2017 06:51 PM

    Thanks Colin. 

     

    I understand and like I mentioned above: the client does trust the ClearPass, Root CA, intermediate CA certs.



  • 4.  RE: TLS with AD and CPPM in between

    Posted Jan 22, 2017 06:57 PM
    Did add your internal Root CA to the Clearpass certificate trust list ?

    Get Outlook for iOS


  • 5.  RE: TLS with AD and CPPM in between

    Posted Jan 22, 2017 06:59 PM

    I wonder if you read my post. LoL

    The answer is Yes, all certs are in the Trusted lint of ClearPass PEAP functions with no problem, only TLS is not working.



  • 6.  RE: TLS with AD and CPPM in between

    EMPLOYEE
    Posted Jan 22, 2017 07:02 PM

    If there is an unknown ca error, either the client does not trust the CA of the server cert or the Radius server does not trust the CA that issued the cert of the client.  You need to figure out which situation is the problem.



  • 7.  RE: TLS with AD and CPPM in between

    EMPLOYEE
    Posted Jan 22, 2017 07:12 PM
    Which certificate is the signing CA for the client cert?


  • 8.  RE: TLS with AD and CPPM in between

    Posted Jan 22, 2017 07:16 PM

    The intermediate is the signing CA.



  • 9.  RE: TLS with AD and CPPM in between

    Posted Jan 22, 2017 07:16 PM
    I think you misunderstood what I have suggested earlier.

    In Clearpass you need to add the AD Root CA if AD is the one issuing your clients certs ?

    Get Outlook for iOS


  • 10.  RE: TLS with AD and CPPM in between

    Posted Jan 22, 2017 07:24 PM

    Got it.

    In ClearPass I have the root CA certificate added. As well as the intermediate CA. They are added to ClearPass Trusted list of certificates.