Security

last person joined: 19 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboard - TLS Issues, User not found

This thread has been viewed 10 times
  • 1.  Onboard - TLS Issues, User not found

    Posted May 30, 2017 02:02 AM

    Clearpass VA (ESXi) with Onboarding version 6.6.5.93747

    so trying to setup onboarding using a single SSID.. 

     

    I have used the wizard to create the necessary services and policies. 

    I have then created the necessary networks, CA Server and onboarding profiles. 

     

    I have modified the pre-provisioning Enforcement profile to allow me to authenticate to AD for the PEAP portion of the process. 

     

    I have then tested this with a windows 10 machine, the peap works fine and i can get to the onboarding page and download the software. I can run the software and get a Certificate installed (under the user's Certificate store) and the computer gets configured to then connect using TLS.

     

    But the TLS Authentication fails with the error message

    Error Code: 201
    Error Category: Authentication failure
    Error Message: User not found
     Alerts for this Request  
    RADIUS
    [Onboard Devices Repository] - localhost: User not found.
    [Guest User Repository] - localhost: User not found.
    EAP-TLS: Authentication failure, unknown user

     

    I have looked under onboard and the user is registered and the device is registered as well.. 

     

    What am i missing...



  • 2.  RE: Onboard - TLS Issues, User not found

    EMPLOYEE
    Posted Jun 09, 2017 08:39 PM

    Make sure your identity store is added as an authentication source.

     

    Also, dual SSID onboarding is recommended in most cases.



  • 3.  RE: Onboard - TLS Issues, User not found

    Posted Oct 10, 2017 08:24 AM

    I´ve got this exact issue, did you manage to solve it ?



  • 4.  RE: Onboard - TLS Issues, User not found

    Posted Oct 10, 2017 09:56 AM

    Anyone got any tips ?

    My computer I´m testing with doesn´t get connected. Access tracker shows errorcod 201 "User not found"

    But I managed to onboard a iphone. Problem is auth. source showes Active Directory instead of Onboard database.

     

    Service has auth sources: onboard database, active directory, and a mac-list (in that order)

     

    Very strange... 



  • 5.  RE: Onboard - TLS Issues, User not found

    Posted Oct 10, 2017 10:51 AM

    ok, so I managed to get my computer to work also by adding user name strip :/ 

    But auth source in access tracker showes AD as source...

    But if I revoke the cert i get denied. So is this how it should be by design ? I thought onboard database would show as source. 

     

    How does your access tracker look for onboarded devices ?

     

    Am I missing something ?

     



  • 6.  RE: Onboard - TLS Issues, User not found

    EMPLOYEE
    Posted Oct 10, 2017 08:06 PM

    The only authentication source that should be defined would be your identity store (Active Directory).



  • 7.  RE: Onboard - TLS Issues, User not found

    Posted Oct 11, 2017 02:34 AM

    Ok, so devices are actually not authenticated against the onboard database. The certificate is the mechanism controlling the access for them ?

     

    So should I need to strip /:user to actually make this work ? Can´t remember having this in there before and it has worked before.



  • 8.  RE: Onboard - TLS Issues, User not found

    EMPLOYEE
    Posted Oct 11, 2017 07:32 AM
    All the certificate does it replace the user password. The user is still authorized against the identity store.


  • 9.  RE: Onboard - TLS Issues, User not found

    Posted Oct 11, 2017 08:04 AM

    Great thanks, now I understand the proccess better.



  • 10.  RE: Onboard - TLS Issues, User not found

    Posted Oct 31, 2018 08:48 AM

    Hi

     

    So what should be correct Authentication Sources for 802.1x wired access for computers added with OnBoard? Having only Onboard Devices Repository ends with: " Alerts for this Request
    RADIUS [Onboard Devices Repository] - localhost: User not found.
    EAP-TLS: Authentication failure, unknown user"

    I would like to accomplished the screnerio where I deliver only machine certificate and the computer authorizes before the user login.

     

     



  • 11.  RE: Onboard - TLS Issues, User not found

    EMPLOYEE
    Posted Oct 31, 2018 08:53 AM
    No auth source.


  • 12.  RE: Onboard - TLS Issues, User not found

    Posted Oct 31, 2018 05:02 PM

    The auth source is set to Onboard device repository.

    Should I add another one?



  • 13.  RE: Onboard - TLS Issues, User not found

    EMPLOYEE
    Posted Oct 31, 2018 05:27 PM
    No, you shouldn's have any auth sources if you're not using user credentials.