Security

last person joined: 10 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Cluster certificate question?

This thread has been viewed 10 times
  • 1.  ClearPass Cluster certificate question?

    Posted Jul 26, 2015 03:55 AM

    Hi Forum,

     

    I'm working on a cluster of two nodes only(Publisher and subscriber with a VIP). I have read the Cert Tech note and I think Danny has done a great job on that document. I followed his recommendations on the cluster certificate section -page 26 and on-

    The question I have is:

    Can I use the same publicly signed certificate for both SSL and RADIUS .1x authentication? Would the .1x clients get an error because the CN is for the DATA(guest) VIP interface and not the MGMT interface that they are reaching the box on?

    I'm not sure I can get two publicly signed certs for DATA and MGMT interfaces, so can I reuse and what's the downside?

     

     

    Thanks in advance,

     



  • 2.  RE: ClearPass Cluster certificate question?
    Best Answer

    EMPLOYEE
    Posted Jul 26, 2015 09:38 AM
    Yes you can use the same certificate for both radius and web. Also, the port does not matter since the common name for 802.1X does not have to match the DNS name.


    Thanks,
    Tim


  • 3.  RE: ClearPass Cluster certificate question?

    Posted Jul 26, 2015 04:08 PM

    Thank you Tim, Can the same publicly signed cert be installed on the both nodes? or do I need to use the same CSR to get two different certs one for each box?



  • 4.  RE: ClearPass Cluster certificate question?

    EMPLOYEE
    Posted Jul 26, 2015 04:12 PM
    Yes, as long as both FQDNs are subject alternative names.


  • 5.  RE: ClearPass Cluster certificate question?

    Posted May 25, 2016 11:36 PM