- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
2 weeks ago
By using ClearPass, certificate is distributed to clients so that the client can access the network (EAP TLS). Clients can access the network by using distributed certificate. Once a client accessed the network, is there any way to deny that client from accessing the network by making the distributed certificate invalid? Thanks in advance.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
2 weeks ago
Hi Syazusyazu923,
of cause there is a way. Key words are CRL or OCSP.
Greetings
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Clear Pass certification
2 weeks ago
Thanks!
I will check the information about OCSD in ClearPass!
@airsecxd wrote:Hi Syazusyazu923,
of cause there is a way. Key words are CRL or OCSP.
Greetings
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Clear Pass certification
2 weeks ago
Hi. I already configured authentication method to use the tls with ocsp enabled. In the ocsp settings, I inserted the ocsp URL, and successfully revoked the certificate. Unfortunately, I was unable to unrevoked the certificate so that the client can access the network again. Please give me some suggestion or hint. Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Clear Pass certification
a week ago
As I understand certificate rules, revoke is one-way. To "unrevoke" you re-issue a new certificate.
if I've helped, please give kudos
if I've provided a solution, please mark the solution so others can find it
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Clear Pass certification
a week ago
As msabin stated, you can not "unrevoke".
Your client needs to request and receive a new certificate from the PKI.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Clear Pass certification
Thursday
Thank you very much!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Clear Pass certification
Thursday
Again, thanks a lot! Finally got the answer for my question!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator