Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass database cert renewal

This thread has been viewed 31 times
  • 1.  Clearpass database cert renewal

    Posted Dec 06, 2022 04:21 AM
    I have a Clearpass cluster with two members. The database certificate has expired causing the cluster to break. I am going to renew the database certificate with a self signed one and reboot the publisher. I am looking for some help on the process required.
    After i update the publisher certificate, will the subscriber rejoin the cluster or do I need to import the certificate to it first?
    Will I need to drop the subscriber and re-add to the cluster?


  • 2.  RE: Clearpass database cert renewal
    Best Answer

    Posted Dec 06, 2022 04:43 AM
    Hi

    Depending on how long time the database certificate have been invalid the subscriber can automatically reconnect to the publisher. If the certificate expired less than 24 hours ago the subscriber will hopefully connect back to the Publisher without any issues.
    But if the time is more than 24 hours since the certificate become invalid, you must drop the subscriber and make it a subscriber again.

    If needed to drop the subscriber, do not clear the configuration. This way you will have the correct certificates installed in the trust list needed to make it a subscriber again.

    ------------------------------
    Best Regards
    Jonas Hammarbäck
    ACCX #1335, ACMP, ACDP, ACNSP, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 3.  RE: Clearpass database cert renewal

    Posted Dec 06, 2022 07:02 AM
    Ok, its more than 24 hours so I will need to drop the subscriber.


  • 4.  RE: Clearpass database cert renewal

    Posted Dec 06, 2022 08:07 AM
    Do I drop the subscriber first, then update the certificate or does it not matter?


  • 5.  RE: Clearpass database cert renewal

    Posted Dec 06, 2022 08:20 AM
    Hi

    I don't think it matter, because you have already lost the communication between the two nodes.
    You may need to drop the node on both from the publisher and the subscriber side due to the lost communication. Start from the publisher side and see if the subscriber can react to the operation. If not, drop it also from the subscriber.

    Check also the second checkbox in the drop subscriber dialog to retain the configuration of the server.

    During the operation to drop and the following operation to make it a subscriber again, the server will not be able to respond to authenitcation requests.
    If your network infrastructure, such as switches and WLAN, doesn't have redundant Radius configuration you should perform the operation outside office hours.

    Also keep in mind that if the cluster have VIP addresses configured, you need to remove the VIP configuration from the subscriber before the drop is tried.

    ------------------------------
    Best Regards
    Jonas Hammarbäck
    ACCX #1335, ACMP, ACDP, ACNSP, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Clearpass database cert renewal

    Posted Dec 06, 2022 08:37 AM
    Thanks for this. Just a couple more things to confirm please :)
    If I need to drop the subscriber from the subscriber side it would be via the CLI using 'cluster drop-subscriber' command? I don't think there is a way via the GUI
    and lastly, I only need to update the database certificate on the Publisher, correct? Or do I need to do something on the subscriber too?​


  • 7.  RE: Clearpass database cert renewal

    Posted Dec 06, 2022 08:51 AM
    If you need to drop on the subscriber node you can do it both from GUI and the CLI.
    From the GUI you find the option under Administration\Server Manager\Server Configuration. Select the radio button for the subscriber and click the Drop Subscriber button to the far right.

    If the database certificate for the subscriber is ok, you do not need to update this certificate.

    ------------------------------
    Best Regards
    Jonas Hammarbäck
    ACCX #1335, ACMP, ACDP, ACNSP, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 8.  RE: Clearpass database cert renewal

    Posted Dec 06, 2022 09:03 AM
    Great thank you. I think the subscriber cert is out of date too so will update it as well.