Security

Reply
Contributor I
Posts: 25
Registered: ‎07-01-2014

Verify Onboard certificate MAC address

Hoping someone here might have an answer to this.  When a client is Onboarded, the MAC address of the device is placed into the SAN field (Certificate:Subject-AltName-DirName-OnboardMACAddress) of the certificate.  Is there a way either through a role mapping or through an enforcement policy to verify that the requesting device MAC (Connection:Client-Mac-Address-Colon) is the same MAC that is listed in the SAN? 

Guru Elite
Posts: 8,188
Registered: ‎09-08-2010

Re: Verify Onboard certificate MAC address

[ Edited ]

Yes, you can, however not all iOS devices have the MAC in the cert.

 

certificate-mac-addr-match.png


Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor I
Posts: 25
Registered: ‎07-01-2014

Re: Verify Onboard certificate MAC address

[ Edited ]

Any hints on how to accomplish this?  Never mind, the image was not showing up.

Guru Elite
Posts: 8,188
Registered: ‎09-08-2010

Re: Verify Onboard certificate MAC address

[ Edited ]

certificate-mac-addr-match.png


Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor I
Posts: 25
Registered: ‎07-01-2014

Re: Verify Onboard certificate MAC address

Thats the same configuration I have except it does not work.  Do you have any other ideas?

Guru Elite
Posts: 8,188
Registered: ‎09-08-2010

Re: Verify Onboard certificate MAC address

Did you verify that the certificate has the SAN? Does it have multiple MAC addresses? You may need to change the operator to belongs_to or contains.

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor I
Posts: 25
Registered: ‎07-01-2014

Re: Verify Onboard certificate MAC address

I guess I lied when I said mine was the same. I was using EQUALS, should have been using EQUALS_IGNORE_CASE. 

 

Thanks for your help, working like it should.

Search Airheads
Showing results for 
Search instead for 
Did you mean: