Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass problems with COMODO certs?

This thread has been viewed 1 times
  • 1.  Clearpass problems with COMODO certs?

    Posted May 06, 2014 10:56 AM

    Anyone ever have any problem loading up a COMODO server cert to Clearpass?



  • 2.  RE: Clearpass problems with COMODO certs?

    EMPLOYEE
    Posted May 06, 2014 11:04 AM
    What exactly is the issue? Are you getting an error on import or is it a
    client issue?


  • 3.  RE: Clearpass problems with COMODO certs?

    Posted May 06, 2014 12:15 PM

    I have been working with Dave Dipert from DNS and we have figured that the cert is properly installed into CPPM in the correct chain of trust order (otherwise it won't accept it when you try to upload it). However when ever I connect with a win7 device i get this error:

     

    Cert Error CPPM.PNG

     

    So now we are not quite sure where to go from here...



  • 4.  RE: Clearpass problems with COMODO certs?

    EMPLOYEE
    Posted May 06, 2014 12:39 PM
    That's the client side server certificate check for PEAP. You either need
    to manually configure the client with the appropriate certificate and
    server trusts or use a supplicant configuration utility like QuickConnect


  • 5.  RE: Clearpass problems with COMODO certs?

    Posted May 06, 2014 12:44 PM

    Ok, thats where we were headed as a conclusion as well. Question to you Tim, would a cert from another vendor have the same problem? Would the easiest solution be getting a cert from say GoDaddy or Verisign for example? Or do you think there is an issue with the individual cert we purchased?



  • 6.  RE: Clearpass problems with COMODO certs?

    EMPLOYEE
    Posted May 06, 2014 12:51 PM
    All certificates will do this. Each SSID profile on a device has a trusted
    CA and trusted server name. If the CA that issues your server cert is not
    preconfigured for that SSID profile, you will get that warning.

    All it's saying is: do you trust this server so I can send your credentials
    to it?


  • 7.  RE: Clearpass problems with COMODO certs?

    Posted May 06, 2014 12:54 PM

    You suggested using Quickconnect, would Onboarding (since I have the licenses) take care of it as well? (I am a CPPM noob incase you couldn't tell LOL)



  • 8.  RE: Clearpass problems with COMODO certs?

    EMPLOYEE
    Posted May 06, 2014 12:57 PM
    QuickConnect is a standalone dissolvable product that handles supplicant
    configuration without the need to onboard. It's good for basic
    peap-mschapv2 and ttls. If you are doing certificate authentication and
    enrollment (EAP-TLS) you should use CP OnBoard.


  • 9.  RE: Clearpass problems with COMODO certs?

    EMPLOYEE
    Posted May 06, 2014 12:54 PM
    This message often reads as an error but its a normal part of the EAP-PEAP process