Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Server Certificate is gonna expired

This thread has been viewed 1 times
  • 1.  Clearpass Server Certificate is gonna expired

    Posted Dec 11, 2014 02:15 AM

    Dear all experts,

    Due to my customer is using Clearpass and he told me that "Server Certificate" is gonna expired. So last night i came to fix this problem like these steps :

    1. Generate CSR from CPPM side by goto  Administration » Certificates » Server Certificate and Create Certificate Signing Request
    2. Upload CSR file that just generate from CPPM side to Onboard side by goto Home » Onboard + WorkSpace » Management and Control » View by Certificate and click Upload Certificate Signed Request
    3. And i export Certificate file from Onboard side and import it back to CPPM side. The result is  an expiry Date will be extended to Dec 11,2015. That the old one is gonna expired in 18 Dec 2014.
    4. I tried to test with following these cases :
        4.1 802.1x with notebook installed Win7 and Win8. They can successfully authenticated and work fine.
        4.2 Guest authentication by using the same notebook Win7 and Win8. They can work fine too.
        4.3 Iphone authentication with onboard , it can work fine.
        4.4 Android authentication with onboard, it can't work. It showed me like an attachment file error.

     

    It look like Android already been provisioned but it died on the last authentication step about bad certificate.

     

    Could you please advice me how to check or fix it?

     

    Thanks very much,



  • 2.  RE: Clearpass Server Certificate is gonna expired

    EMPLOYEE
    Posted Dec 11, 2014 02:36 AM
    Did you try a reboot after the new cert was installed?


  • 3.  RE: Clearpass Server Certificate is gonna expired

    Posted Dec 11, 2014 03:26 AM

    Yes , i did it. But still got the problem. Is it correct for my implementation step ??



  • 4.  RE: Clearpass Server Certificate is gonna expired

    Posted Dec 11, 2014 03:57 AM

    Hi Troy,

     

    Do we need to do anything at Android phone or anywhere else on CPPM or Onboard module?

     



  • 5.  RE: Clearpass Server Certificate is gonna expired

    EMPLOYEE
    Posted Dec 11, 2014 07:13 AM
    Your setup sounds fine but how are you exporting the cert from the onboard side. I would use pem and include the full trust chain


  • 6.  RE: Clearpass Server Certificate is gonna expired

    EMPLOYEE
    Posted Dec 11, 2014 07:17 AM
    Also if you are reonboarding the android I would open the network and provisioning setting and resave so a new package is built.


  • 7.  RE: Clearpass Server Certificate is gonna expired

    Posted Dec 11, 2014 08:52 AM

    Oh!!! i export from onboard side with crt file, not pem file. And how can i include full trust chain from exporting?