Security

last person joined: 16 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

EAP-TLS and checking user is not disabled or locked in AD

This thread has been viewed 2 times
  • 1.  EAP-TLS and checking user is not disabled or locked in AD

    Posted Apr 21, 2016 04:45 PM

    Hello,

    I'm looking to create a service/policy that uses EAP-TLS to authenticate user and machine certificates but for authorization ensures that the account is still in good standing in Active Directory.  Currently we're pulling the Subject CN and I have the policy authenticating valid certificates, but it's still authorizing the user regardless of the status of their account.  I've done this with other Radius products, just trying to figure out how to do it the CPPM way ;)

     

    Thanks,

    Greg



  • 2.  RE: EAP-TLS and checking user is not disabled or locked in AD

    Posted Apr 21, 2016 05:07 PM
    In the AD auth source you add the userAccountControl and use that attribute either (512 enabled or 514 disable) in your enforcement policies

    Sent from Outlook for iPhone


  • 3.  RE: EAP-TLS and checking user is not disabled or locked in AD

    Posted Apr 25, 2016 01:24 PM

    Thanks Victor,

    I think your answer is on the right track.  Can you send me some extra details on how to configure this?

     

    Sorry for the lengthy gap, it's been a busy week of projects lately.

     

    Thanks,

    Greg



  • 4.  RE: EAP-TLS and checking user is not disabled or locked in AD

    EMPLOYEE
    Posted Apr 21, 2016 05:08 PM

     

    In your EAP-TLS authentication method, you would make sure that "authorization required" is enabled.  My apologies if you have already tried that.

     

    http://www.arubanetworks.com/techdocs/ClearPass/Aruba_CPPMOnlineHelp/index.htm#CPPM_UserGuide/Auth/AuthMethod_eap-tls.htm?Highlight=eap-tlsauthorization