Security

last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - EAP-PEAP, checking devices have the RootCA.

This thread has been viewed 0 times
  • 1.  Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 04, 2014 07:19 AM

    Hi,

     

    I have a customer who wants just a basic EAP-PEAP for their byod, and for them it will be simply internet only after authenticating.

     

    That is simple enough, but the problem is that they have an internal CA, so the devices won't have the RootCA installed.  I don't want devices to uncheck the 'validate server certificate' since that is an insecure config.  IT will probably install the RootCA for them, or we'll make available somewhere for them to do themselves.

     

    I was wondering if there is some logic in Clearpass that I can build an enforcement rule to check if the device has installed and using the RootCA?

     

    We'll be doing onboarding separately for non-domain devices that need access to the corporate network, so for those it is fine.



  • 2.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 04, 2014 07:30 AM
    No, you can't check if it's there. It's a client-level construct. From the perspective of the server, it doesn't care about the Root CA on the device. It's a client-level check. Sometimes you'll get "unknown CA" as an alert in access tracker which is reported from the client which usually indicates they don't have it or they're configured with the wrong CA.


  • 3.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 04, 2014 09:56 AM

    ok, got it.  I thought as much.

     

    What about onboarding, but pushing a network config of EAP-PEAP?  Would that push the RootCA to the device during the process?  Would that consume an onboard licence, given a client cert has not actually been generated?

     

    The only other time I've done this setup, the customer had a public cert, so the trust relationship was already there.



  • 4.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 04, 2014 09:58 AM
    Are you doing single SSID onboarding?


  • 5.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 04, 2014 10:01 AM

    Haven't quite decided on that yet.  It will likely be a separate ssid, or a link on the guest login page.



  • 6.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 04, 2014 10:04 AM
    This is really what QuickConnect is designed for.


  • 7.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 05, 2014 01:45 AM

    ok, that's fair enough.

     

    Just so I'm clear, when you connect an iOS device to an EAP-PEAP connection, the error that pops up about the server not being trusted, once you accept, it is then trusted?  I mean if the device goes away and then there is a rogue ssid with rogue server, will it refuse to connect, or is it a case of the error pops up again?  Sorry, I'm not an Apple person.

     

    Not sure about Android, or at least the versions I've tried, they just seem to accept any certificate without warning.

     

    Anyhow, just to explain the implications to the customer and be able to offer Quickconnect if need be.



  • 8.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.
    Best Answer

    EMPLOYEE
    Posted Aug 05, 2014 07:15 AM
    The box that pops up is not an error. It's a normal part of the PEAP process. Certificate trust with PEAP is per connection profile (per SSID). That dialog is simply saying, do you trust this server to send your credentials.

    If you use QuickConnect, the profile is configured/installed in the background so they never see that box.


  • 9.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 06, 2014 03:23 AM

    got it.  Quickconnect sounds like the way forward.

     

    Thanks



  • 10.  RE: Clearpass - EAP-PEAP, checking devices have the RootCA.

    EMPLOYEE
    Posted Aug 06, 2014 07:26 AM

    ok, so the Quickconnect subscription, is it per user or per device?