Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Timeline of Renewal for Radius Cert once Extracted from CPPM.

This thread has been viewed 17 times
  • 1.  Timeline of Renewal for Radius Cert once Extracted from CPPM.

    Posted Nov 08, 2021 11:49 AM
    Hi Community,

    Just want to have some opinions from others regarding the timeline of a Radius Certificate should be renewed and import to CPPM once CSR  is extracted (Create Certificate Signing Request) from it.

    Thanks in advance!

    Rj


  • 2.  RE: Timeline of Renewal for Radius Cert once Extracted from CPPM.

    Posted Nov 08, 2021 12:21 PM
    Hi Enrique,

    Not sure I understand your question but giving it a try..

    Your certificate is good until it expires or you deploy a new one. With respect to timing, once you generate the CSR, it's up to the certificate signing authority (unless you are doing a self-sign cert) to issue the certificate. This could be minutes to hours.

    Once you have the new cert, the install takes seconds basically.

    Hope this helps - Ricardo.


    --
    °(((=((===°°°(((================================================





  • 3.  RE: Timeline of Renewal for Radius Cert once Extracted from CPPM.

    MVP GURU
    Posted Nov 08, 2021 01:48 PM
    If your asking how much time you have between generating the CSR on clearpass and installing it, its 15 days.

    A certificate signing request created in ClearPass is valid for only 15 days. After 15 days, the CSR expires and the certificates that were created by it cannot be installed. Also note that the stored private key is removed 15 days after the certificate signing request was created. If you don't import the certificate within 15 days, you must create the CSR and certificate again.

    https://www.arubanetworks.com/techdocs/ClearPass/6.8/PolicyManager/Content/CPPM_UserGuide/Admin/ServerCertificate_Create_Certificate_Signing_Request.htm



    ------------------------------
    Dustin Burns
    Lead Mobility Engineer @WEI

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 4.  RE: Timeline of Renewal for Radius Cert once Extracted from CPPM.

    Posted Nov 08, 2021 09:24 PM
    Thank you for answering the question. My superiors doesn't believe me that Renewed Cert should be installed within 15 days of generating the CSR.

    Rj




  • 5.  RE: Timeline of Renewal for Radius Cert once Extracted from CPPM.

    MVP GURU
    Posted Nov 09, 2021 08:39 AM
    No problem. Glad I could help.

    ------------------------------
    Dustin Burns
    Lead Mobility Engineer @WEI

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------