Security

last person joined: 9 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboard CPPM as intermediate - what template to sign csr

This thread has been viewed 1 times
  • 1.  Onboard CPPM as intermediate - what template to sign csr

    EMPLOYEE
    Posted Aug 08, 2014 11:40 AM

    Hi,

     

    I'm trying to setup Clearpass for onboarding as an Intermediate CA.  Have generated the CSR, but wondering what sort of template needs to sign this from a Microsoft CA?

     

    The error I'm getting is 'Certificate is not a CA'.

     

     



  • 2.  RE: Onboard CPPM as intermediate - what template to sign csr

    Posted Aug 31, 2014 07:43 PM

    Me too, ClearPass 6.3.

     

    I have tried with both User and Web Server templates, but same error "Certificate is not a CA"



  • 3.  RE: Onboard CPPM as intermediate - what template to sign csr
    Best Answer

    EMPLOYEE
    Posted Sep 01, 2014 12:26 AM

    You need to make sure the account you use to log into the cert srv page has the correct rights. You need to reqest a sub ca.

     

    Here is what it should look like if you have the full admin rights.

     

    Screen Shot 2014-08-31 at 11.23.04 PM.png



  • 4.  RE: Onboard CPPM as intermediate - what template to sign csr

    Posted Sep 01, 2014 03:32 AM

    Just to add a few thoughts in addition to what tarnold said.

     

    Make sure the user you are requesting the certificate with have the Enroll security access on the template.

    • MMC CA console -> Certificate Templates -> Right-click Sub CA Template / Properties / Security. Verify that the user you are logged in with have Enroll properties
    • If OK - try to run the browser with Run as command to get the Domain Admin access, unless you have the rights on your user 

    Make sure the template is actually Published.

    • MMC CA console -> <name-of-ca-server> -> Certificate Templates
    • Is it listed here? If not - Expand <name-of-CA> and right-click the Certificate Templates folder -> choose New / Certificate Template to Issue. Select the Subordinate CA template and click OK

     

     



  • 5.  RE: Onboard CPPM as intermediate - what template to sign csr

    Posted Sep 02, 2014 04:00 PM

    Kudos both tarnold and jsolb. Good solution and advise



  • 6.  RE: Onboard CPPM as intermediate - what template to sign csr

    EMPLOYEE
    Posted Oct 13, 2014 07:20 AM

    ok, finally got back round to having a go at this, and having some probs.

     

    Customer has signed the request with the subordinate template.

     

    So I click on 'Install certificate'

    clearpass-intermediate CA.jpg

     

    And then try to import it, but it just gives this error.

     

    clearpass- ca import.jpg



  • 7.  RE: Onboard CPPM as intermediate - what template to sign csr

    EMPLOYEE
    Posted Oct 13, 2014 07:47 AM

    ok, the original CSR was generated many weeks ago and seems there is a timeout.

     

    I deleted the CA and then started again, and then the import worked fine.  :-)