Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can't OnBoard a second user on MacBook

This thread has been viewed 0 times
  • 1.  Can't OnBoard a second user on MacBook

    Posted Dec 05, 2019 02:18 PM

    We are trying to OnBoard different users on the same MacBook and can't get this to work.

     

    The first user OnBoards without problem, but when we try another user, the user is assigned the correct radius role to start the OnBoarding process but it times out.

     

    The Alerts Tab in ClearPass shows:

    Error Code: 9002

    Error Category: RADIUS protocol

    Error Message: Request Timed Out

    RADIUS: Client did not complete EAP transaction

     

    The Provisioning Settings for macOS Profile Type is user

     

    Appreciate any input anyone can provide.

     

     

     



  • 2.  RE: Can't OnBoard a second user on MacBook

    EMPLOYEE
    Posted Dec 05, 2019 03:19 PM

    Onboard is not really designed to be used per-user on shared devices. Are these organizationally owned devices?



  • 3.  RE: Can't OnBoard a second user on MacBook

    Posted Dec 05, 2019 03:36 PM

    Yes, these are company owned devices.



  • 4.  RE: Can't OnBoard a second user on MacBook

    EMPLOYEE
    Posted Dec 05, 2019 07:09 PM

    Onboard Assisted Provisioning is not designed for this. It's designed for unmanaged, personal devices.

     

    You should issue certificates via your management platform.



  • 5.  RE: Can't OnBoard a second user on MacBook

    Posted Feb 03, 2020 08:14 AM

    Hi,

    We have similar situation (multiple users on Macbook device, TIMEOUT on CPPM during MSCHAP phase) in our environment, but instead being corporate our devices are personal.

     

    Having in mind what you said before, would the way around be to load cert issued by CPPM to secondary account manually? Thanks in advance.