Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Issue with CPPM and Aruba AP with wildcard certificate

This thread has been viewed 24 times
  • 1.  Issue with CPPM and Aruba AP with wildcard certificate

    Posted Apr 13, 2021 11:36 AM

    Hello,
    I've been having an issue with the integration of a CPPM to manage guest and specific access to Wifi using some Aruba AP.
    I was able to upload properly the wildcard and CA certificate on both sides.
    I can access the guest login page without any issues when prompted, but once i insert the credentials it shows me a warning message saying that

    XXX.mydomain.tld is not using a valid domain, the certificate receive was *.mydomain.tld. (more or less, it is in french, sorry )



    I think it is related to the "Captive portal server" certificate, because if i remove it on my Aruba VC, the message change, identifiying  the default securelogin.arubanetworks.com for the certificate.

    The question is : how do i configure things properly so that i do not receive the warnings ?

    This also brings another question, as i am not quite sure about how the whole thing works as an exchange, is someone can confirm the flow ?

    Customer hooks up on the wifi
    > gets prompted with the captive portal page on the CPPM
    > login > gets forwarded back to the AP VC ?
    >VC sends back the credentials/additional information to CPPM

    > CPPM validates credentials, sends back the policy/roles to AP VC that finally allows user devices to communicate properly within the limits of the roles?

    Thanks in advance,

    Xavier



    ------------------------------
    Xavier Sirard
    ------------------------------


  • 2.  RE: Issue with CPPM and Aruba AP with wildcard certificate

    MVP GURU
    Posted Apr 14, 2021 08:42 AM
    Bonjour Xavier,

    if you have a wildcard certificate, you need to set captiveportal-logon.mydomain.tld (and not vc)

    do you have check also if you have the chain of this certificate ?

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 3.  RE: Issue with CPPM and Aruba AP with wildcard certificate

    Posted Apr 14, 2021 09:07 AM

    Hello,

    I saw that afterward, changed it to captiveportal-login.domain.tld (assuming it is login and not logon as your wrote).

    I have the chain of the certificate and wildcard, uses the same pair for CPPM without issues.

    I found out (while tcpdumping from my test Macbook) that it was trying to reach a virtual IP of a temp DHCP server i had on the VC.
    Once i removed it in the conf, the android device started to work.

    However the mac still dont want it.

    I have opened a TAC with Aruba, spent a few hours already with them, double checking all basics configuration.

    They've tried tweaking a few things here and there.


    I can access the wifi just fine, the CPPM portal too, but i still have the same issue on the Mac.

    I was not able to confirm with them, but i do not know if it is normal that my test macbook is talking to 172.31.98.1 (which appear to be some kind of default IP for the AP) ?

    Any leads is interesting to follow.

    Thanks,



    ------------------------------
    Xavier Sirard
    ------------------------------



  • 4.  RE: Issue with CPPM and Aruba AP with wildcard certificate

    EMPLOYEE
    Posted Apr 14, 2021 09:29 AM
    It could be that you just imported the server (wildcard) certificate into your VC. You will need to add the intermediates (chaining) before the import.

    Check here on how to create that chained certificate (you have one, so you can skip the CSR and request part).

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 5.  RE: Issue with CPPM and Aruba AP with wildcard certificate

    MVP GURU
    Posted Apr 14, 2021 09:43 AM
    +1 with Herman, check if you have also the chain on the certificate push on VC (do you have Airwave or central for manage ?)

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------