Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

OnBoard Failing for Macbook Laptops

This thread has been viewed 2 times
  • 1.  OnBoard Failing for Macbook Laptops

    MVP
    Posted Dec 17, 2014 02:43 PM

    Customer wanted to OnBoard company owned devices to do TLS authentication. I have ClearPass and the IAP cluster configured. OnBoard works successfully on Windows laptops, we have it working on 1 Macbook (took 4 hours of trying and didn't really change anything). 

     

    Device connects to SSID-Secure (WPA2-Enterprise against AD) enters credentials, then put in pre-provisioning role (OnBoard captive portal), user logs in (against AD) and follows OnBoarding steps. 

     

    When it tries to install the certificate we receive "Cannot decrypt encrypted profile" and it does not connect. 

     

    I have debugging turned on in the OnBoard plugin, and the application logs do not show anything too strange, except a few re-sends of the phases. 

     

    Any ideas why this may be happening? I'm close to calling TAC, but thought I would try this first.



  • 2.  RE: OnBoard Failing for Macbook Laptops

    Posted Dec 17, 2014 04:00 PM

    This is while you trying to install the profile ?



  • 3.  RE: OnBoard Failing for Macbook Laptops

    MVP
    Posted Dec 17, 2014 04:03 PM

    Correct, we receive that error while installing the profile.



  • 4.  RE: OnBoard Failing for Macbook Laptops

    Posted Dec 17, 2014 04:04 PM
    Have you tried disabling https and instead using HTTP ?



  • 5.  RE: OnBoard Failing for Macbook Laptops
    Best Answer



  • 6.  RE: OnBoard Failing for Macbook Laptops

    MVP
    Posted Dec 17, 2014 04:16 PM

    Testing now, will update shortly.

     

    Thanks!



  • 7.  RE: OnBoard Failing for Macbook Laptops

    EMPLOYEE
    Posted Dec 17, 2014 04:18 PM
    Do you have a publicly signed web server certificate?


  • 8.  RE: OnBoard Failing for Macbook Laptops

    MVP
    Posted Dec 17, 2014 04:19 PM

    Customer purchased a SSL cert from DigiCert that we installed for RADIUS authentication and I am using that for the OnBoard certificate as well.



  • 9.  RE: OnBoard Failing for Macbook Laptops

    MVP
    Posted Dec 17, 2014 04:26 PM

    So it looks like with HTTP, we were able to install the profiles successfully. We had to manually disconnect and reconnect for the TLS authentication to succeed. We are going to test a few more devices just to verify.



  • 10.  RE: OnBoard Failing for Macbook Laptops

    Posted Dec 17, 2014 04:37 PM

    Not sure how you can fix that with the an IAP but in the controller side of things , if you include the IP address of the controller (captive portal) it allows you do that.

     

    2014-12-17 16_36_15-L3 Authentication.png



  • 11.  RE: OnBoard Failing for Macbook Laptops

    MVP
    Posted Dec 17, 2014 04:53 PM

    It appears that using HTTP instead of HTTPS has resolved the profile installation issue. From a security perspective, the profile installation is unencrypted, but once that is complete and the TLS authentication takes place, that will be encrypted from that point correct?



  • 12.  RE: OnBoard Failing for Macbook Laptops

    Posted Dec 17, 2014 05:13 PM
    That's correct