Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Terminating EAP-TLS on ClearPass

This thread has been viewed 4 times
  • 1.  Terminating EAP-TLS on ClearPass

    Posted Sep 05, 2017 01:30 PM

    Dear Community,

     

    1. is it possible to terminate EAP-TLS  based on only the CA certificate without a connection to the radius/ca server that produced the client certificate ..?

     

    ** if CA certificate is enough for authentication how can we update the

    CPPM on revoked certificate ..?

     

    2. can we use the ClearPass to create client certificates for the devices?

     

    * it would be nice to get a related best practice documents / tutorials.. 

     

     

    Thanks a lot!

    Shay



  • 2.  RE: Terminating EAP-TLS on ClearPass
    Best Answer

    EMPLOYEE
    Posted Sep 05, 2017 01:33 PM
    1) Yes, but not having revocation checks really defeats the point

    2) Yes, the ClearPass Onboard module is for issuing certificates to unmanaged devices.


  • 3.  RE: Terminating EAP-TLS on ClearPass

    Posted Sep 05, 2017 01:41 PM

    Hi Cappalli , 

     

    thank you for your quick response :)

     

    so is there any way to manually load updates with the revoked certificates?

     

     



  • 4.  RE: Terminating EAP-TLS on ClearPass

    EMPLOYEE
    Posted Sep 05, 2017 01:44 PM
    You need to use your CA's OCSP responder (or you can use the CA's CRL, but OCSP is recommended).


  • 5.  RE: Terminating EAP-TLS on ClearPass

    Posted Sep 05, 2017 02:12 PM

    by saying "need to use your CA's OCSP responder" 

    how can i use it if i cant configure any connectivity to the ca/radius .. ? 

    is it possible to use the ClearPass as OCSP responder by loading manually updates from the CA server to the ClearPass server ? 

     



  • 6.  RE: Terminating EAP-TLS on ClearPass
    Best Answer

    EMPLOYEE
    Posted Sep 05, 2017 02:24 PM

    No. ClearPass is an OCSP responder for it's own CAs only.

     

    ClearPass would need to communicate with your CA's OCSP responder or CRL endpoint.



  • 7.  RE: Terminating EAP-TLS on ClearPass

    Posted Jan 15, 2019 07:33 PM
    Tim, If I go to Administration --> Certificates --> Revocation LIsts and add the Distribution URL of my CA for CRL's and check "update whenever CRL is updated" that should be good too yes? I guess other than OCSP it's only as good as that CRL file get's updated on that Web Server, Yes? Why would OCSP be reccomended above that. Also do you have any OCSP AD/ClearPass app notes?