Security

 View Only
  • 1.  sponsored onboarding via clearpass

    Posted Nov 23, 2023 05:50 AM

    We  run a sponsored guest service where  guest usage required someone to click "yes"   on a web page.

    Would it be possible to do this device (wired) onboarding?  We're in a position where we want end users. to move to eap-tls but need someone to approve the onoboarding before it starts so that only  devices that satisfty an approval process can have a certificate installed.

    ... or do i try and front end the onboarding solution with another sponsored guest  type setup for wired connectivity so we have a special guest setup that points you at cppm onboard.

    A



  • 2.  RE: sponsored onboarding via clearpass

    Posted Dec 05, 2023 08:19 AM

    Is this about ClearPass Onboard? Note that ClearPass Onboard is for BYOD/unmanaged devices. If you have your devices under management, it's probably better to get certificates enrolled via that path (Group Policies/MDM).

    You can enable sponsorship for Onboard directly in the last tab of the provisioning configuration:



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: sponsored onboarding via clearpass

    Posted Dec 05, 2023 09:38 AM
    Hi,
    Yes we already use GPO to push cert to domain joined devices and that works a treat. This is for situation where we have standalone devices that needn’t cert based auth to wired network. Was thinking about joining our cpp cluster to the enterprise PKI infrastructure and the using ppm to install certs on. These standalone devices if possible.

    Many thanks for the info, never noted the sponsored bit on onboarding … will have a play
    A




  • 4.  RE: sponsored onboarding via clearpass

    Posted Dec 05, 2023 10:26 AM
    Ok cool! Found that … looks good.

    Another question. Can we integrate clearpass with a. Thales Luna S750s HASM module for secure key storage
    A




  • 5.  RE: sponsored onboarding via clearpass

    Posted Dec 06, 2023 11:50 AM

    I don't think there is HSM support in ClearPass. You may check/open a request on Aruba Innovation Zone.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------