Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Any workaround for EAP-TLS forcing a username check against an auth source?

This thread has been viewed 2 times
  • 1.  Any workaround for EAP-TLS forcing a username check against an auth source?

    Posted Apr 03, 2016 07:52 PM

    I am building an EAP-TLS service.Have done this many times before and normally check the CN in the certificate against another source such as Active Directory.

    However in this project there will be potentially tens of different origins of valid certificates, and there is no single auth source to check them against. Moreover we don't actually want to check any client CNs at all - we only care about other attributes of the certificate which will be checked in the enforcement stage.

    And we don't want to maintain any list of valid client CNs as there will be thousands and they are managed separately.

    Bottom line, Clearpass requires we select an authentication source in the service definition. The certificate CN gets mapeed to Authentication:Username and checked against this source. Is there a workaround where Clearppas can accept any CN without checking an auth source?

     



  • 2.  RE: Any workaround for EAP-TLS forcing a username check against an auth source?
    Best Answer

    EMPLOYEE
    Posted Apr 03, 2016 07:56 PM
    Created a custom auth method and disable comparison and authorization. Then just throw AD in there because you have to define a source.

    Sent from Nine<>


  • 3.  RE: Any workaround for EAP-TLS forcing a username check against an auth source?

    Posted Apr 03, 2016 08:03 PM

    Perfect. I added Local User Repository which is empty and works fine.

     

    I almost looked up what that checkbox did, but the term authorization threw me - not quite the correct term to use there. 

     

    thanks Cappalli