Security

 View Only
  • 1.  clearpass 6.10 backup of certs

    Posted Oct 12, 2021 12:02 PM
    Hi All,

    I was under the impression that in 6.10  a server backup also backed  up the certificates installed on the machine.

    Just upgraded a server from 6.10.1 -> 6.10.2 and did a config backup

    Built a new 6.10.2 VM differnt IP address

    Restored the config to it - no certs restored

    Was 6.10 supposed to backup/restore certs ?
    A

    ------------------------------
    Alex Sharaz
    ------------------------------


  • 2.  RE: clearpass 6.10 backup of certs

    Posted Oct 13, 2021 06:17 AM
    Certificates are not part of a ClearPass backup (or not of the restore, but end result is the same). Other well-known things that are not part of the CPPM backup are the domain join and licenses.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: clearpass 6.10 backup of certs

    Posted Oct 13, 2021 08:05 AM
    This is why certs don't belong in backups: horizon3ai/vcenter_saml_login: A tool to extract the IdP cert from vCenter backups and log in as Administrator (github.com)

    ------------------------------
    Tim C
    ------------------------------



  • 4.  RE: clearpass 6.10 backup of certs

    Posted Oct 13, 2021 02:18 PM
    Ok good reason :-)

    Following on from that , also thought I’d read that 6.10 purges endpoints “N” days after last seen on network instead of 1st seen. Which makes more sense
    Hi Sent from my iPhone