Security

last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Verify Onboard certificate MAC address

This thread has been viewed 2 times
  • 1.  Verify Onboard certificate MAC address

    Posted Sep 03, 2014 03:24 PM

    Hoping someone here might have an answer to this.  When a client is Onboarded, the MAC address of the device is placed into the SAN field (Certificate:Subject-AltName-DirName-OnboardMACAddress) of the certificate.  Is there a way either through a role mapping or through an enforcement policy to verify that the requesting device MAC (Connection:Client-Mac-Address-Colon) is the same MAC that is listed in the SAN? 



  • 2.  RE: Verify Onboard certificate MAC address
    Best Answer

    EMPLOYEE
    Posted Sep 03, 2014 03:30 PM

    Yes, you can, however not all iOS devices have the MAC in the cert.

     

    certificate-mac-addr-match.png



  • 3.  RE: Verify Onboard certificate MAC address

    Posted Sep 03, 2014 03:33 PM

    Any hints on how to accomplish this?  Never mind, the image was not showing up.



  • 4.  RE: Verify Onboard certificate MAC address

    EMPLOYEE
    Posted Sep 03, 2014 03:34 PM

    certificate-mac-addr-match.png



  • 5.  RE: Verify Onboard certificate MAC address

    Posted Sep 03, 2014 03:42 PM

    Thats the same configuration I have except it does not work.  Do you have any other ideas?



  • 6.  RE: Verify Onboard certificate MAC address

    EMPLOYEE
    Posted Sep 03, 2014 03:51 PM
    Did you verify that the certificate has the SAN? Does it have multiple MAC addresses? You may need to change the operator to belongs_to or contains.


  • 7.  RE: Verify Onboard certificate MAC address

    Posted Sep 03, 2014 04:12 PM

    I guess I lied when I said mine was the same. I was using EQUALS, should have been using EQUALS_IGNORE_CASE. 

     

    Thanks for your help, working like it should.