Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Active Directory authentication source Cache

This thread has been viewed 17 times
  • 1.  Clearpass Active Directory authentication source Cache

    Posted Apr 19, 2021 10:40 AM
    What's actually cached for a given AD authentication source?

    Is this the "UserDN" information that would include group membership?  Is the actual user authentication credential's cached?


    ------------------------------
    Scott Farrand
    ------------------------------


  • 2.  RE: Clearpass Active Directory authentication source Cache

    Posted Apr 19, 2021 11:52 AM
    CPPM does not store user credentials for external sources.

    ------------------------------
    Tim C
    ------------------------------



  • 3.  RE: Clearpass Active Directory authentication source Cache

    EMPLOYEE
    Posted Apr 26, 2021 05:50 AM
    I would say it is safe to assume that it is the information that is displayed in Access Tracker for your Authentication source, including Groups/memberOf and other attributes that are pulled from AD.

    As mentioned, credentials are not part of that.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 4.  RE: Clearpass Active Directory authentication source Cache

    Posted Apr 26, 2021 10:06 AM
    My issue wasn't that the credentials were being stored... my issue was that we test primary group membership as part of our login policy, and I'd missed the "Cache Timeout" section of the General tab under Authentication Sources.

    I was just trying to figure out why an AD primary group membership change didn't show up quickly in ClearPass.  That Cache Timeout was the reason.

    ------------------------------
    Scott Farrand
    ------------------------------