Security

 View Only
last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cleasrpass guest user registration issue

This thread has been viewed 11 times
  • 1.  Cleasrpass guest user registration issue

    MVP EXPERT
    Posted May 28, 2021 03:09 AM
    Hi All,

    Not sure if this is the right discussion group ... could well be the mobility controller group.

    I've inherited a clearpass sponsored guest system covering multiple sites which as far as I know has been working just fine .... up till recently. At one site the whole process works just fine till you get to the display of the created user credentials with the login button. When you click login the end user gets a certificate error and the initial login fails. As this fails, the subsequent  mac caching setup also fails.

    On the controller concerned there is 1 certificate defined and its assigned to the controller web interface and the captive portal setup. I *think* its just a cert and the controller doesnt have a full CA chain installed.

    From the user perspective he's connecting to <fqdn>/cgi-bin/login which resolves to another server,  but the certificate he sees in his browser is an aruba self signed one for the controller in question ( you can see the controller serial number in it). Similarly, if you https to the controller ip address the cert you see is also this controller  self signed one.

    Running 6.5.1.18 FIPS on the 7210 controller

    Any help appreciated
    Rgds
    Alex

    ------------------------------
    Alex Sharaz
    ------------------------------


  • 2.  RE: Cleasrpass guest user registration issue

    MVP EXPERT
    Posted May 28, 2021 05:28 AM
    And of course just after I fix it I find this article

    https://community.spiceworks.com/topic/1826231-aruba-guest-wifi-portal-cert-issue



    ------------------------------
    Alex Sharaz
    ------------------------------



  • 3.  RE: Cleasrpass guest user registration issue

    Posted Jun 01, 2021 03:30 AM
    Alex,

    At some point the web redirect changes to captive-portal.login.<domain>

    Derin