Wireless Access

Reply
New Contributor
Posts: 3
Registered: ‎09-21-2015

PAN Integration stops after migrating from 6.4.2.8 to 6.4.3.6.

Hi,

 

Heads up on PAN and Certificate Trust changes

 

I found out through a packet capture that the Aruba controller no longer accepts an untrusted certificate from the firewall.

 

This was ignored in 6.4.2.8, but enforced in 6.4.3.6.

 

I've added the CA Trusted Root and ICA into the Aruba controllers that signed the PAN Web UI, and the PAN XMLAPI is now working again.

 

Regards,

Stephen.

 

Contributor I
Posts: 48
Registered: ‎08-16-2014

Re: PAN Integration stops after migrating from 6.4.2.8 to 6.4.3.6.

I'm still struggling with this issue.  Have tried a self-signed cert on the PAN as well as a GoDaddy wildcard cert.  Both function fine as the cert in place for the PAN's Web UI, but I am not able to make the Aruba controller get happy with the XML-API by loading either of them.  Was there some trick to that?  

New Contributor
Posts: 3
Registered: ‎09-21-2015

Re: PAN Integration stops after migrating from 6.4.2.8 to 6.4.3.6.

I'm using a UCC certificate (i.e. CN=host.domain.name). I wonder whether wildcard may be unsupported, and whether a self-signed certificate might need the FQDN (or IP address) to be included in the CN or SAN fields.

 

In either case, capturing the TLS negotiation will show the failure reason via the Alert codes, either the server rejecting the client, or the client rejecting the server.

 

You could also use the openssl toolkit to help troubleshoot TLS server problems, see command "openssl s_client -connect paloaltohost.domain.com:443".

 

Contributor I
Posts: 48
Registered: ‎08-16-2014

Re: PAN Integration stops after migrating from 6.4.2.8 to 6.4.3.6.

I tried swapping back and forth between a wildcard cert, a self signed cert, and changing from IP to hostname on the self-signed cert.  Eventually, it started working with the self-signed when I deleted and re-entered the PA config section.  So it seemed to me that you have to delete and recreate your PA info AFTER uploading the certificate.  *shrug*

New Contributor
Posts: 3
Registered: ‎09-21-2015

Re: PAN Integration stops after migrating from 6.4.2.8 to 6.4.3.6.

Probably need to redo config to remove and load the new cert into memory.

 

I would think a controller reboot would also accomplish the same thing, but who can afford the downtime.

 

Search Airheads
Showing results for 
Search instead for 
Did you mean: