Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Create guest account after disabling

This thread has been viewed 36 times
  • 1.  Create guest account after disabling

    Posted Nov 16, 2020 12:30 PM

    We have configured a guest portal where any guest can self-register using their phones as username. The behavior after expiration is "disable and logout" and we have also disabled the auto update field in the form, because we want that one phone only can register one account (with 3 devices allowed). The system shows an error message if the same phone try to register again.

    In this scenario everything is working fine, however after expiration the same phone cannot create another account because it already exists in the accounts list. This is not real, because it exists but it is disabled (expired).

    We know that we can change the behavior after expiration to "delete and logout", but we need to keep the list of old usernames. So, we have to avoid two phones registering twice during the account lifetime and we have to allow that this phone can create another account after expiration (disabled account).



  • 2.  RE: Create guest account after disabling

    EMPLOYEE
    Posted Nov 17, 2020 12:27 PM
    Is there a question that you'd like to be commented on?

    ------------------------------
    Carson Hulcher
    ------------------------------



  • 3.  RE: Create guest account after disabling

    Posted Nov 18, 2020 11:02 AM
    Everything is explained in my post.

    Is it possible that any disabled username (phone) can register again without duplication username error?  We use "disable and logout" after expiration and the auto update field is disabled.





  • 4.  RE: Create guest account after disabling

    EMPLOYEE
    Posted Nov 18, 2020 11:41 AM
    To register the account a second time requires allowing the auto update.

    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Create guest account after disabling

    Posted Nov 18, 2020 12:13 PM
    We don't want to use the auto update because we want to avoid that people can register again and again and the system has to send the credentials by SMS again and again, maybe using the registration form to hack the system. It is more intuitive for users to see a message which say that they have already created an account with the same phone.

    We just need the system to understand that any disabled account is not an active account, so the system should let to enable it when someone register again. We think that considering a disabled (expired) account like an "existing" account is not logical, people cannot really use this account to connect but cannot create another one.

    These are the conditions:
    Account doesn't exist -> Let to register, create the account and send credentials. 
    Account exists and is enabled-> Don't let to register and show a message.
    Account exists and is disabled (expired) -> Let to register, enable the account again, update the expiration time and send new credentials.

    We think that our point of view is not strange.




  • 6.  RE: Create guest account after disabling

    EMPLOYEE
    Posted Nov 18, 2020 12:25 PM
    That isn't how the guest registration works in ClearPass.

    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Create guest account after disabling

    Posted Nov 23, 2020 11:49 AM
    Maybe it is not how the guest registration works but this is our need and we are asking for a solution. If every time someone raises a need is not given a solution then we would still be in version 1.

    Another question. Is it possible to close the session to all devices connected with same account in case of resetting the password through self-service portal? We use MAC Caching so we should close and mark the devices as "unknown" again.

    ------------------------------
    Juan Manuel Castrejo
    ------------------------------



  • 8.  RE: Create guest account after disabling

    EMPLOYEE
    Posted Nov 23, 2020 12:17 PM
    The answer right now is to allow auto-update of the registered account which means having to live with the fact that there will be a password reset that goes along with that.

    I'd recommend that if you would like to see a change in the behavior then you should post an idea to https://innovate.arubanetworks.com/.

    I'm fairly certain that changes via SSP don't interact with sessions.  MAC caching shouldn't be determinant on known vs unknown but rather the state of the relevant account and/or the expiry information added to the endpoint entry.

    Is there a particular behavior or issue (other than the account update) that you are trying to resolve?

    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------