Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Authorising devices with ":n:Onboarddevice" username

This thread has been viewed 0 times
  • 1.  Authorising devices with ":n:Onboarddevice" username

    Posted Aug 06, 2014 07:42 PM

    Have just implemented an onboard solution but we've now lost the ability to put users into roles based on their AD username since the android network settings replace this with ":n:Onboarddevice"

     

    I notice that the common name on each user's cert is still their AD username. Is it possible to use this attribute of the certificate in an enforcement policy using AD authorization?



  • 2.  RE: Authorising devices with ":n:Onboarddevice" username

    EMPLOYEE
    Posted Aug 06, 2014 07:48 PM

    You should be able to.  Are you using TLS for Onboard?  If so, then the username within the TLS cert is preserved and then used for AD authorization.



  • 3.  RE: Authorising devices with ":n:Onboarddevice" username

    EMPLOYEE
    Posted Aug 06, 2014 07:49 PM
    The identity is still passed as the user's username. The certificate is simply their secured password. Do you have AD as an authorization source in your EAP-TLS service?


  • 4.  RE: Authorising devices with ":n:Onboarddevice" username

    Posted Aug 06, 2014 07:51 PM
      |   view attached

    So this mainly affects android which still uses PEAPafter onboarding.

     

    Our ios devices sitll have the correct username, but definitely the outer identity is being replaced with ":n:Onboardevice" for all android certs, where 'n' is the serial number of the certificate being created by onboard.

     

    How can I access the common name attribute in the cert? It's not present under the onboard devices repo.

     

    edit: screenshot for proof :)



  • 5.  RE: Authorising devices with ":n:Onboarddevice" username

    EMPLOYEE
    Posted Aug 06, 2014 07:52 PM

    Can you please try to use TLS for the Android devices as well?  



  • 6.  RE: Authorising devices with ":n:Onboarddevice" username
    Best Answer

    EMPLOYEE
    Posted Aug 06, 2014 07:54 PM
    What version are you running?

    Android should be using TLS as well.

    The certificate information is available under the "Certificate" source.


  • 7.  RE: Authorising devices with ":n:Onboarddevice" username

    Posted Aug 06, 2014 07:57 PM

    Ok thought it was just a limitation.. will try changing to TLS in the network protocol settings..

    This customer is running latest 6.3.4.

    cheers



  • 8.  RE: Authorising devices with ":n:Onboarddevice" username

    Posted Aug 06, 2014 08:02 PM
      |   view attached

    It worked, kudos to you both.

     

    Probably the default settings for android (and windows?) should be updated to TLS.

     

     



  • 9.  RE: Authorising devices with ":n:Onboarddevice" username

    EMPLOYEE
    Posted Aug 06, 2014 08:04 PM

    As of 6.4 all the defaults for network settings are TLS

     

    Screen Shot 2014-08-07 at 12.15.08 AM.png