Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Time Source in Clearpass 6.3

This thread has been viewed 4 times
  • 1.  Time Source in Clearpass 6.3

    Posted May 20, 2014 09:36 PM

    All,

     

    Just curious. Has anyone implemented the new Time Source in Clearpass 6.3? If so, would you mind sharing the use case?

     

    Thanks!

     

    -Mike



  • 2.  RE: Time Source in Clearpass 6.3

    EMPLOYEE
    Posted May 21, 2014 07:43 AM
    Where is that defined?


  • 3.  RE: Time Source in Clearpass 6.3

    Posted May 21, 2014 08:20 AM

    Hi Colin,

     

    It's defined under:

     

    CPPM > Configuration > Authentication > Sources > [Time Source]

     

    I've looked at the methods available with it in a service and allows you to do things like "Now" and now plus a future time - which all seem cool.

     

    The reason I'm asking is that I'm doing a project with a client where we will be presenting a web login page to a connected user after X period of time, no matter what. Arubapedia has an article about Anonymous Guest Logins and pulling it off with an additional SQL db. It would be cool if this new auth source had something similar built in without going the whole way of creating a new db.

     

    Thanks!

     

    -Mike



  • 4.  RE: Time Source in Clearpass 6.3

    EMPLOYEE
    Posted May 21, 2014 08:45 AM
    I believe that is for looking at the expiration date of a cert so you can force a user to a captive portal if a cert is about to expire. I'll look when I get to my office later today.


  • 5.  RE: Time Source in Clearpass 6.3

    Posted May 21, 2014 11:26 PM

    Edited/Removed 

     

     

     

     



  • 6.  RE: Time Source in Clearpass 6.3

    EMPLOYEE
    Posted May 21, 2014 11:28 PM
    I've had it in every version of 6.3 I vaguely remember hearing about what
    Troy mentioned with certificate expiration.


  • 7.  RE: Time Source in Clearpass 6.3

    Posted May 21, 2014 11:36 PM

    Yea, sorry about that.  I initially thought it did not exist on my system, but was on page 3 of my Sources.     I'll step aside for Troy to offer his commentary on it.



  • 8.  RE: Time Source in Clearpass 6.3

    MVP
    Posted May 22, 2014 12:04 PM

    Looks pretty much like the solution tarnold and amigodave managed to conceive for my issue where certificate users did not know their certificate was about to expire.

     

    They created a sql source so I could look at the certificate expiration time and do calculations on it to pop up a captive portal when it was about to expire. 

    see http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/Handling-certificate-expiration/m-p/93548/ for this.

     

    This new TimeSource looks pretty much like that old sql source so I'm guessing they added this so people wouldn't have to pester tarnold and amigodave anymore whenever somebody wanted to do something with time :)



  • 9.  RE: Time Source in Clearpass 6.3

    EMPLOYEE
    Posted May 22, 2014 04:29 PM

    Sorry for the delay here, I’m waiting on a confirmation from engineering. Yes it could be used to check for cert expiration, but it was built to be more universal for other cases. As soon as I here back on some of the other use cases I will let everyone know. 



  • 10.  RE: Time Source in Clearpass 6.3

    Posted Jun 10, 2014 08:23 PM

    Hi Troy,

     

    I wanted to see if the developers replied back about the Time Source?

     

    Thanks for the help!

     

    -Mike



  • 11.  RE: Time Source in Clearpass 6.3

    EMPLOYEE
    Posted Jun 10, 2014 11:23 PM
    Quick note from engineering

    1. Certificate expiry checks
    2. AD account expiry checks (the policy engine can convert the accountExpires attribute into a usable date/time field)

    You can use these to frame policies that look up date/time attributes, and compare them with attributes fetched from authentication/authorization.


  • 12.  RE: Time Source in Clearpass 6.3

    Posted Jun 11, 2014 08:27 AM

    Troy,

     

    Would you use the "%{Time-Source:Now}" type format in order to do this check?

     

    Thanks!

     

    -Mike