Security

last person joined: 13 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Configure certs manually on end users

This thread has been viewed 0 times
  • 1.  Configure certs manually on end users

    Posted Nov 30, 2016 05:45 PM

    Hi,

     

     I'm trying to provision the users manually in an onboard deployment, but not sure 100% how to create the cert and install it.

     

     I provisioned an user with the QuickConnect and it worked fine, then desconfigure the wireless properties on the network card to set it manually and reconfigure again as how it set with the quickconnect but id didn't work.

     

     When create a cert on the onboard, download it and install on the end user laptop but after configure the properties and try to connect it asks for credentials, as on the accesstracker always see "user:<number>:OnboardDevice" I think I must access with this user but it doesn`t work with the AD credentials.

     

    Do you know how should it work or how to set the clearpass and user to make this work?



  • 2.  RE: Configure certs manually on end users

    EMPLOYEE
    Posted Nov 30, 2016 05:48 PM
    Are using the full Onboard process or are you generating the certs on the ClearPass side, exporting them and then importing them to the clients?

    Be sure your network configuration in Onboard is set to EAP-TLS and not PEAP.


  • 3.  RE: Configure certs manually on end users

    Posted Nov 30, 2016 05:52 PM

    Hi, 

    I need to generate on the cp onboard, export and import on a windows laptop.

     

     With the full process it works but this is something my end cust doesn't want.



  • 4.  RE: Configure certs manually on end users

    EMPLOYEE
    Posted Dec 01, 2016 02:39 PM

    Are you seeing that username in the cert as well when you look at it on the computer or in Onboard?

     

    Also, when manually doing the CSR, are you using the username as the common name?