Controllerless Networks

last person joined: 16 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Does public certificate require for IAP cluster for clearpass guest

This thread has been viewed 6 times
  • 1.  Does public certificate require for IAP cluster for clearpass guest

    Posted Apr 30, 2017 02:29 PM
    Hi,

    I am going to integrate Clearpass Guest with IAP cluster and I have public certificate on clearpass server so I just want to know that do I require public certificate for my IAP cluster too?


  • 2.  RE: Does public certificate require for IAP cluster for clearpass guest

    EMPLOYEE
    Posted Apr 30, 2017 03:33 PM

    Its not manditory/required to have public signed certificate to be installed on IAP for Clearpass Guest.

     

    In clearpass, we have two certificates https/radius. We can have self-singed for https, if you are OK with client brower warning messages  but make sure to have public singed radius certificate which is used for EAP-TLS/EAP-PEAP authentication.

     

    Regards,

    Pavan



  • 3.  RE: Does public certificate require for IAP cluster for clearpass guest

    Posted Apr 30, 2017 04:15 PM
    Hi Pavan,
    Thanks for response.

    As per clearpass guest workflow, clearpass send response back to secure login.arubanetworks.com and which resolved to virtual controller host name so if that vc don't have the public certificate then crome and iOS user will not able to redirect to desire URL.


  • 4.  RE: Does public certificate require for IAP cluster for clearpass guest

    EMPLOYEE
    Posted May 01, 2017 05:32 AM

    Hi,

     

    I havent come across such issue, it should work. Client will be displayed with warning message when they click submit button on captive portal page.

     

    If you dont want client to see any warning messages during redirections, I would recommand to have public certificate both on IAP and CPPM.

     

    Regards,

    Pavan



  • 5.  RE: Does public certificate require for IAP cluster for clearpass guest
    Best Answer

    EMPLOYEE
    Posted May 01, 2017 08:46 AM

    Just some clarification here.

     

    You should always use a public CA-signed certificate for HTTPS in ClearPass. The EAP server certificate can be either public or private depending on your environment.

     

    You should also always use a public CA-signed certificate for captive portal on the IAP-VC / controller.



  • 6.  RE: Does public certificate require for IAP cluster for clearpass guest

    Posted May 01, 2017 10:21 AM
    Hi Cappalli,

    I am using clearpass guest with IAP so should I require https public signed certificate on Clearpass and IAP both ?


  • 7.  RE: Does public certificate require for IAP cluster for clearpass guest

    EMPLOYEE
    Posted May 01, 2017 10:33 AM