Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Guest captiveportal must Require Public Certificate from CA?

This thread has been viewed 14 times
  • 1.  Guest captiveportal must Require Public Certificate from CA?

    Posted Oct 21, 2019 10:33 PM

    Hi  I need to know about the Public Certificate Installation in Captiveportal.

    Why must installation certificate from CA on Captiveport?

    Someone can explain Reasons to support buying certificate from CA.



  • 2.  RE: Guest captiveportal must Require Public Certificate from CA?

    MVP EXPERT
    Posted Oct 22, 2019 04:14 AM

    ** EDIT - Added tech note **

     

    You will want the client to encrypt any traffic to the Captive Portal via HTTPS. The Certificate shipped with an Aruba Controller/Instant/CPPM is not publicly signed, therefor you will see certificate warnings/errors/unexpected client behaviour. Generally you do not have control over devices accessing a Captive Portal (e.g Guest users) so there for you will need a Publicly signed certificate. This Root CA who has signed the certificate is more than likely already included in the devices Trust store/list of the device in question.

     

    A short while ago, the shipped certificate was revoked. Take a look at the below, it contains some additional useful information.

     

    https://community.arubanetworks.com/t5/Controller-Based-WLANs/ArubaOS-Default-Certificate-Revocation-FAQ-Controllers/ta-p/275809

     

    https://community.arubanetworks.com/aruba/attachments/aruba/aaa-nac-guest-access-byod/14977/1/CPPM%20-%20Certificates%20101%20Technote%20V1.0%20.pdf