If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Aug 01, 2024 03:12 AM
From: manurangas
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Is this correct setting if you have subject-cn intune deviceId on certificate ?

Original Message:
Sent: Jul 03, 2023 07:20 AM
From: Herman Robers
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
You should create the filter based on the Subject-CN, and the CN should contain the Intune Device Id CN={{DeviceID}}
That is not the default for Intune SCEP requests, so needs to be changed. I don't think you can use a SAN for the lookup.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jun 28, 2023 07:55 AM
From: Bertrand017
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Hi All
Greet. We change the Radius Flow to RADSEC and it works fine now.
Thank you very much for your advice.
Our problem was due to radius fragment packet and not the certificate.
And after we need to change the attribute filter to %{Certificate:Subject-AltName-URI}

So it works fine, but we have a little warning on the logs due to the attribute filter:

We are looking on it. Do you have an idea ? We use the Intune Extensions v6.0.3
Very thanks for your help.
Original Message:
Sent: Jun 26, 2023 03:27 PM
From: Mflowers@beta.team
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Can you go to:
Administration -> Certificate Store -> Server Certificates -> Make sure RADIUS/EAP is selected as the type
Take a screenshoot of this and post it.
I use 505s in our environment as well and do not have issues with SCEPman but our RADIUS cert is signed by Godaddy.
Original Message:
Sent: Jun 26, 2023 06:04 AM
From: Bertrand017
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Hello
Thanks for your confirmation that you use SCEPMAN for PKI. And it Works Fine.
Dis you do a particular things ?
For us We just generate a CSR and sign it with Scepman CA.
Our Microsoft and IPhone device is enroll with intunes.
The device certificate and the CA certificate is present on the endpoint.
If you want to see I add an access tracker log on this post.
On the client side we take a capture and we have a lot of Request, Identity and Response, Identity

If We look on the 802.1X process we sould see an EAP-Request / Type or it isn't present on the capture.

So on the Clearpass Capture the Radius : Access Challenge is present.
We are try to take capture on the access point.
Is it possible that there is a Radius configuration Problem for EAP on the Access Point (IAP505 managed by Central).
We try radius authentication for MPSK and it works fine.
Then I can expect that the VPN Site to site is good betwenn the AP and the Clearpass on Azure.
We try the authentication 802.1X with a switch and we have the same error.
Thanks for your help.
Regards.
Original Message:
Sent: Jun 23, 2023 08:42 AM
From: Mflowers@beta.team
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
I use SCEPman with EAP-TLS and it works correctly.
What does the access tracker logs in Clearpass look like when you try to connect?
Original Message:
Sent: Jun 22, 2023 08:42 AM
From: Bertrand017
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Hi
Yes the CA is present on the client side.
We use SCEPMAN version enterprise for the CA and the Clearpass CSR was signed by the CA.
For the windows client configuration we try to choose the radius certificate without success.
So we decide to leverage the test level and don't check the CA certificate or Radius.
But were is the same error.
From the packet capture we see that after receive the server certificate the client restart the authentication process.
I asked this case to a colleague and he thinks that this information is mandatory on the certificate server:
1.3.6.1.5.5.7.3.2 (id-kp-ClientAuth)
So perhaps SCEPman is not a good choice for the PKI.
This is the configuration on the client side for our last test:

Computer authentication and WPA2 AES

Thanks for your help.
Regards
Original Message:
Sent: Jun 22, 2023 01:51 AM
From: OS66
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Hello ,
Can you give us the configuration of adaptor settings on the machine . Because i suspect there is missing configuration on it .
Original Message:
Sent: Jun 15, 2023 05:37 AM
From: VG67
Subject: ClearPass integration with Azure for Intune devices enrollement TLS Issue
Hi All
We are doing a POC ( Proof of concept ) for a customer.
The customer is using Central for managing IAP APs505
And we have deployed a Clearpass in Azure with INtune , Intune Extension is working fine and we are getting end point
But when trying authenticate a client to the SSID with the Clearpass in TLS it seems that the Wifi Client is not accpeting the certificates from Clearpass Server
In access Tracker the Issue is :
Alerts -
Error Code: 9002
Error Category: RADIUS protocol
Error Message: Request timed out
Alerts for this Request -
RADIUS: Last EAP Packet Processing Time = 0 ms
RADIUS: Client did not complete EAP transaction
In Pcap file from Clearpass it 's like APs -> CLearpass are always challenging the Radius authentication
We are using the Filter below and using the Certificat:Subjec-CN

We are thinking that the issue is due to the PKI , but we didn't find any precision concerning the way of what to put in the CSR
Does anyone has already perform it and could give their feed back ?
Many Thanks for your help