- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
02-19-2014 07:39 AM
Hi,
I doing a Clearpass POC for a end customer, he want to see the device enrollment fonctionnality for their IPad.
I have a error for to enroll my IPad by the onboard, when i want download the profile for connect my IPad on the corp network, the Device Enrollment is not accept by the IPad.
At the end of "onboard deploy guide" i found workaround (see below), but it's not clear for me.
Could you explain exactly me what i must to do for step by step ?
"Resolution: When using HTTPS for device provisioning, you must obtain a commercial SSL certificate.
Self-signed SSL certificates, and SSL server certificates that have been issued by an untrusted or unknown root certificate
authority, will cause iOS device provisioning to fail with the message “The server certificate for … is invalid”.
A workaround for this issue is to install an appropriate root certificate on the iOS device. This root certificate must be the
web server’s SSL certificate (if it is a self-signed certificate), or the certificate authority that issued the SSL certificate. This is
not recommended for production deployments as it increases the complexity of deployment for users with iOS devices."
Thanks
Yann
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
02-19-2014 08:19 PM - edited 02-19-2014 08:20 PM
I you have a test environment and want to use Apple IOS device you must install the Root certificates on the mobile device before you try to onboard.
I would recomend that you work with your local SE, but here are the main items
1. You can disable both https on the controller and CPPM Guest side Home » Configuration » Authentication uncheck use https for Guest
2. Or you can take the certificate that is on the CPPM side. Administration » Certificates » Server Certificate
3. Either use Itunes and put the cert on the device or you can just email the cert to your device and install it by
A. opening the email.
B. tap on the attachment and click install
Troy
--Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.
--Problem Solved? Click "Accepted Solution" in a post.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Onboard : iOS Device Provisioning Failures
02-26-2014 04:22 AM
In addition to what tarnold said in point 1 - on IOS make sure you use Safari when trying to enroll. Using Chrome it doesn't work at all.
I don't see a reason to use a public certificate for onboarding. The onboarding process tells you to first install the trusted root CA certificate. First do that - then onboard - works like a charm.
Regards
John Solberg
-ACMX #316 :: ACCX #902 :: ACSA
Aruba Partner Ambassador
Intelecom/NetNordic - Norway
----------------------------
Remember to Kudo if a post helped you! || Problem Solved? Click "Accept as Solution" in a post!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Onboard : iOS Device Provisioning Failures
03-24-2014 10:35 AM
Hi Tarnold,
I try your two solution but it doesn't work ...
1. You can disable both https on the controller and CPPM Guest side Home » Configuration » Authentication uncheck use https for Guest
I have disable the https both the CPPM et on my IAP, now the connexion is initialise in http, but it continue to verifying the device inscription before download the connexion profil and after when I click on "installer" and type my code, I get this error message : profile installation failure - profil not valid.
2.
2. Or you can take the certificate that is on the CPPM side. Administration » Certificates » Server Certificate
In my Clearpass is initial configuration (it's the root certifcate), I take the https and radius certificate.
3. Either use Itunes and put the cert on the device or you can just email the cert to your device and install it by
A. opening the email.
B. tap on the attachment and click install
I send the cetificate by an email and i install this certificate by clicking on install, but it has not changed...
Have you an idea ?
Regards
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Onboard : iOS Device Provisioning Failures
03-24-2014 10:40 AM
Hi jsold,
for your information I use only Safari on the Ipad ...
I would try to show to my customer how work the Onboard with IPad, it's not the final instal, the best that I can get a trusted root in trial version for free.
Regards
Yann
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Onboard : iOS Device Provisioning Failures
08-02-2017 10:59 PM
Hi,
I have been experiencing problems provisioning iOS devices with iOS versio 10.3.3. This is the latest version so far. I keep getting the error message as shown in the attached screenshot. Previous iOS version (10.2.1) didn't give this issue. Please help me on this.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Onboard : iOS Device Provisioning Failures
08-02-2017 11:10 PM
Regards
John Solberg
-ACMX #316 :: ACCX #902 :: ACSA
Aruba Partner Ambassador
Intelecom/NetNordic - Norway
----------------------------
Remember to Kudo if a post helped you! || Problem Solved? Click "Accept as Solution" in a post!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Onboard : iOS Device Provisioning Failures
08-03-2017 12:51 AM
Hi John,
Thanks for replying. I'm actually new to the Aruba interface. Would appreciate if you could guide me regarding this.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Onboard : iOS Device Provisioning Failures
08-03-2017 01:27 AM
First make sure you have a dns entry for your clearpass that is resolvable on from the dns server assigned to your onboard clients.
Then create a https certificate that corresponds with this name. If you do this for internal use make sure to rename the fqdn on the clearpass and you could do a self-signed cert from clearpass gui..
Regards
John Solberg
-ACMX #316 :: ACCX #902 :: ACSA
Aruba Partner Ambassador
Intelecom/NetNordic - Norway
----------------------------
Remember to Kudo if a post helped you! || Problem Solved? Click "Accept as Solution" in a post!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator