Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Service Template 802.1x Wired Unknow CA

This thread has been viewed 0 times
  • 1.  Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 05:37 AM

    Hi all,

     

    I configured an default service template "802.1x Wired". When i connect my client i see following error in my Access Tracker:

    Thebiestone_0-1584523873971.png

    I have on my server an self-signed cert. Thats why the error says unknow ca i think. But when i try to add my self-signed cert into Clearpass trusted list i got this:

    Thebiestone_1-1584524017265.png

    But pkcs 12 is the only way i can export my cert from the server?

    Thebiestone_2-1584524069760.png

    Anyone an idea?

    Thanks!

     



  • 2.  RE: Service Template 802.1x Wired Unknow CA

    EMPLOYEE
    Posted Mar 18, 2020 05:45 AM

    , We can convert file to support format manually and upload certificate to server trust list.

    You can use online tool aswell for certificate conversion if it is for POC purpose.

     

    https://www.sslshopper.com/ssl-converter.html



  • 3.  RE: Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 06:05 AM

    Thanks for the reply!

     

    But the error is still the same..

    Any idea? Or can i just delete the self-signed cert.

    Because its just an POC.



  • 4.  RE: Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 06:12 AM

    Does the clearpass has a Radius(service) certificate as well from the same CA?



  • 5.  RE: Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 06:19 AM

    No, i just created on my windows server an self-signed cert and imported this in the root ca on the client. How do i create an radius cert?



  • 6.  RE: Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 06:26 AM
    1. Create a CSR on your clearpass (Administration, Certificates, Certificate Store, create Certificate Signing Request)
    2. Sign it by your CA
    3. import the signed certificate by your CA on the same page in clearpass => Import Certificate)
    4. assign this certificate to your wired service
      Thomasds_1-1584527160008.png

       



  • 7.  RE: Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 06:36 AM

    Sorry, but how can i sign the CSR with my CA?

     

    Thanks!



  • 8.  RE: Service Template 802.1x Wired Unknow CA

    EMPLOYEE
    Posted Mar 18, 2020 06:55 AM

    Check below link on how to submit CSR request to internal AD certificate authority.

    Submit the Request to Active Directory Certificate Services

    https://support.embotics.com/support/solutions/articles/8000035243-generating-and-installing-an-ssl-certificate-with-active-directory-certificate-services

     

     



  • 9.  RE: Service Template 802.1x Wired Unknow CA

    Posted Mar 18, 2020 07:24 AM