Security

 View Only
last person joined: 10 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Guest Certificate Renewal

This thread has been viewed 5 times
  • 1.  ClearPass Guest Certificate Renewal

    Posted 2 days ago

    We're updating the ClearPass guest certificate, and this is my first time handling it. This certificate is used for guest authentication. Besides importing the certificate, is there anything else I need to do? Any help would be appreciated!



  • 2.  RE: ClearPass Guest Certificate Renewal

    Posted 2 days ago

    Hi

    I assume you are referring to the https certificate in ClearPass?

    If so you should pay attention to keep the same SAN names in the new certificate as this certificate is not only utilized for the https traffic for the guests when browsing the captive portal pages, but also the management access to the ClearPass server. If you are using Downloadable User Roles for switches or WLAN, you should also make sure to have the new certificate issued by the same root CA. If not you have to make sure your network infrastructure trust the new CA, or the Downloadable User Role download may stop working.

    If all this is correct, changing the certificate is easy. After the new certificate has been installed it may take up to a few minutes before it has been applied fully.

    Export the old certificate and keep as backup if you need to do a rollback.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------