Cloud Managed Networks

 View Only
  • 1.  Cloud Auth and "losing the certficate", having to re-onboard

    Posted Sep 21, 2024 09:37 AM

    We have a customer that has all Aruba wireless access points (recently upgraded to 6xx.) They were migrated to Aruba's cloud authentication for about two years. We have a majority of Windows 11 notebooks, with a smattering of W10s. The move to Cloud Auth was intentional and a part of reducing the local server footprint and using Microsoft's Entra ID for authentication. We are trying to identify a pattern causing the "loss" of the ability to log in via the Cloud-Auth credentials; specifically, the certificate is "disappearing." I say that because once we re-onboard the notebooks, they start working again. I associate that with the renewed certificate, but maybe incorrectly. Does anyone else see this in their wireless network? They are running AOS10.x. It appears to be a relatively "random" occurrence. One certainty, if a user has been dormant for a couple of weeks, we most likely have to re-onboard.

    Thoughts?



  • 2.  RE: Cloud Auth and "losing the certficate", having to re-onboard

    Posted Sep 22, 2024 02:15 AM

    see if the user's that need to re-onboard have their Entra account disabled at some point due to perhaps inactivity 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Cloud Auth and "losing the certficate", having to re-onboard

    Posted Sep 23, 2024 12:10 PM

    Could it be that the certificate expired while the devices were dormant? Certificates are valid for one year after onboarding, and would need to be renewed/refreshed before they expire. What do the logs in Central show for those devices? Or don't they even connect, by lack of a client certificate?

    Have not heard this, just some Samsung devices that require the Onboard app to be excluded from battery saving as the operating system will otherwise remove the certificate after some time. But have not heard similar for Windows Devices. Could it be that there is device management/security software that removes the client certificate or configuration?

    Have you opened a TAC case for this?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: Cloud Auth and "losing the certficate", having to re-onboard

    Posted Mar 22, 2025 07:26 AM
    Edited by marvin.spiteri@eworld.com.mt Mar 22, 2025 07:28 AM

     Aruba Central cloud auth certs are valid for 1 year, Can anyone confirm if cloud auth certificates are automatically renewed before they expire pls ?  Aruba Central foundation licence includes cloud auth. Is there any limitation on total users allowed to connect ?  Could not find this documented.. 



    ------------------------------
    Marvin Spiteri
    ------------------------------



  • 5.  RE: Cloud Auth and "losing the certficate", having to re-onboard

    Posted Mar 22, 2025 12:21 PM
    We have had a number of "scenarios" where computers have lost the certificates specifically for those that are "cloud only." HPE Aruba has improved the certificate management overall, but nothing is perfect as we all know. Dormancy has alot to do with losing certs. If you think about it, dormancy can be effected/defined from a number of angles:
    • power conditions
    • last sign on
    • last connection to the network (if you have a hybrid network)
    • access rules and policies
    • age of certificate on computing device
    • certificate corruption

    This is a short list of some of the environmental issues that have caused the certs to "disappear" and force re;-onboarding. We have experienced some of the certificates to automatically regenerate for another year. It does make one want to scratch their heads.

    Hope this helps.


     

    "Enhanced Cybersecurity through Consulting"

     

    Michael K. Grady  

      

     3681 Okemos Road - Suite 200 | Okemos, MI | 48864 

    Voice: 517-349-4900 dial 627 for my extension | Fax: 517-349-0983 | Email: mgrady@gracon.com 

    Thank you for supporting a Michigan Small Business, it matters!


     

     






  • 6.  RE: Cloud Auth and "losing the certficate", having to re-onboard

    Posted Mar 23, 2025 01:23 AM

    Yes CloudAuth server certificates are automatically renewed before they expire and based on 

     Aruba Central foundation license includes CloudAuth. Here is the Central subscription ordering guide .

    Currently CloudAuth can provide  cloud-guest portal, dot1x and Mac auth for both CX switches and Aruba APs. when using dot1x auth, you need to configure cloud identity stores as well.  Currently the following identity stores are supported 

    • Microsoft Entra ID
    • Google Workspace
    • Okta Workforce Identity Cloud


    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------