Security

last person joined: 13 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

This thread has been viewed 5 times
  • 1.  IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

    Posted Nov 27, 2017 11:38 PM

    I have been following the Video Tutorials provided by Herman and i have been able to get my clearpass where it will authenticate both PEAP and TLS Windows AD Clients without any issue.

     

    I have moved onto the onboarding and again followed the videos and have been able to successfully onboard a windows client.

     

    When i try to authenticate an IOS or OSX device i get an issue about certificates.

     

    I am using a CP Hosted Root CA.

     

    From what i can see from the profile, the certificates are passed and enabled for trust they just don't connect.

     

    In the logs i get an error about 'TLS_accept:error in SSLv3 read client key exchange A'

     

    I am not sure what is different, when i search on the error a lot of sites indicate that it is issue with the client not trusting the Root CA certificate but from what i can see the certificate is installed as a trusted root ca.

     

    Any advice on how to troubleshoot this.

     

    Thanks

    Attachment(s)

    zip
    WindowsOnboard.zip   7 KB 1 version
    zip
    IOSOnboard.zip   7 KB 1 version


  • 2.  RE: IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

    EMPLOYEE
    Posted Nov 28, 2017 12:04 AM
    Is your EAP server certificate SHA-2?


  • 3.  RE: IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

    Posted Nov 28, 2017 12:14 AM
      |   view attached

    the CA Root Server is SHA512 and the Client Certificates generated from it are SHA512 as well with 2048bit key.

     

    The Radius Client Certificate is SHA1 with 2048bit key.

     

    i have attached example cert

    Attachment(s)

    zip
    byot.test.zip   1 KB 1 version


  • 4.  RE: IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

    EMPLOYEE
    Posted Nov 28, 2017 12:18 AM
    Your EAP server certificate needs to be SHA-2 or higher.


  • 5.  RE: IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

    Posted Nov 28, 2017 06:07 AM

    Hi Seic,

     

    I think you're doing lab testing with ClearPass Onboard feature, so using SHA-512 is not really an issue. If you plan to implement Onboard in a production environment, using SHA-512 for each client cert may cause serious performance issue. I would go for SHA-256 instead.

     

    Thank you,



  • 6.  RE: IOS/OSX Onboard Error, failed in SSLv3 read client certificate A

    Posted Jan 14, 2018 10:19 AM
      |   view attached

    Hi, I have the same question,Can you tell me the solution?