Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

guest cert issues

This thread has been viewed 0 times
  • 1.  guest cert issues

    Posted Aug 18, 2015 10:42 PM

    I just deployed Clearpass guest with PSK. windows users who were previously connected to Guest and now getting certifiacte warning and want to import a new certificate. How can I resolve this so users are not getting the popup warning? 



  • 2.  RE: guest cert issues

    EMPLOYEE
    Posted Aug 18, 2015 10:44 PM
    Do you have a captive portal configured?


    Thanks,
    Tim


  • 3.  RE: guest cert issues

    Posted Aug 18, 2015 10:44 PM

    yes - sorry left that out 



  • 4.  RE: guest cert issues

    EMPLOYEE
    Posted Aug 18, 2015 10:47 PM
    Do you have a public certificate installed?

    If clients are attempting to access a secure site, they will likely get the certificate error. Unfortunately there's no way around this.


    Thanks,
    Tim


  • 5.  RE: guest cert issues

    Posted Aug 18, 2015 10:51 PM

    The cert its using would be the one under CPPM/administration/certificates/server certs ? 

     

    Its a public signed Geotrust cert 



  • 6.  RE: guest cert issues

    EMPLOYEE
    Posted Aug 18, 2015 10:53 PM
    Yes. Unfortunately this will happen if users are trying to access a secure website.


    Thanks,
    Tim


  • 7.  RE: guest cert issues

    Posted Aug 18, 2015 10:55 PM

    Curious, how is it considered secure?  How do I make this unsecure ;-) 

     

    yes I understand the risks



  • 8.  RE: guest cert issues

    EMPLOYEE
    Posted Aug 18, 2015 10:59 PM
    You would have to disable SSL for your captive portal. But you will still get the occasional redirect cert mismatch.


    Thanks,
    Tim


  • 9.  RE: guest cert issues
    Best Answer

    Posted Aug 18, 2015 11:05 PM

    I have the captive portal on the instant controller to use port 80 and disable https. Is there another location? 



  • 10.  RE: guest cert issues
    Best Answer

    EMPLOYEE
    Posted Aug 19, 2015 01:14 PM

    In CPG->Configuration->Authentication uncheck "Require HTTPS for guest access"

     

    Screen Shot 2015-08-19 at 1.10.52 PM.png

     

    This will prevent the client from being redirected from port 80 to HTTPS on the ClearPass side.