Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

download private key on clearpass 6.7

This thread has been viewed 64 times
  • 1.  download private key on clearpass 6.7

    Posted Jun 26, 2018 01:57 PM

    On clearpass 6.6 when you generate the request you were able to download the private key  as on the button it says download csr and private key.   On 6.7 it just says download CSR

     

    How do i get the private key?

    this was really useful to me when generating some .pem files

     

    Cheers

    Carlos



  • 2.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Jun 26, 2018 01:59 PM
    After you install the signed cert, you can export it. There is no need to access the private key until the signed certificate is installed.


  • 3.  RE: download private key on clearpass 6.7

    Posted Jun 26, 2018 02:07 PM

    So there is no way to do that anymore?

     

    And ineed it before because for example if i want a certificate for many controllers and use the same certificate what i did was signing a doing the request

    it get signed

     

    With that i opened a textpad

    Put all the characters of the private key

    then of teh signed cert

    and then the characters of the ca bundle then i put it as a .pem file and i can use that same cert in many controllers. instead of doing them separately

     

    So as you see i dont actually install that cert anywhere before creating the .pem flile

     

     



  • 4.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Jun 26, 2018 02:12 PM
    1) you should never be using the same certificate in ClearPass and network devices

    2) you can't do any of that until you have a signed certificate which is why there is no need to present the private key prior to uploading signed certificate


  • 5.  RE: download private key on clearpass 6.7

    Posted Jun 26, 2018 02:16 PM

    For number 1 i know that, as i once tried and what happened is that when the user was seft registering it just didnt work hehe

     

    for number 2 do i need to install the certificate inthe clearpass to download the private key then??



  • 6.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Jun 26, 2018 02:20 PM
    1) then something is misconfigured
    2) yes


  • 7.  RE: download private key on clearpass 6.7

    Posted Jun 29, 2018 04:19 AM

    Hi Tim,

     

    We've got a 6.6.10 Policy manager running. generated a signing request.. Didnt get the download private key option. but after signing I can't import only the signed certificate because I need the private key it is saying? you've got any idea?

     

    Thnx. 

     

    Joël Stouwdam



  • 8.  RE: download private key on clearpass 6.7

    Posted Aug 18, 2018 09:03 PM

    Same issue here, running 6.7 and I'm trying to import the signed request but it keeps complaining about needing the private key as well. 



  • 9.  RE: download private key on clearpass 6.7

    Posted Aug 19, 2018 04:50 PM

    It’s asking for the key to import on 6.7. I have issued a csr twice using an easy to remember pass phrase and it is not using a “saved” key but instead asking for the file. 

     

    Thanks in advance!



  • 10.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Aug 19, 2018 08:59 PM

     

    Do you see this?

    Screenshot 2018-08-19 at 19.52.21.png

    Screenshot 2018-08-19 at 19.57.28.png



  • 11.  RE: download private key on clearpass 6.7

    Posted Aug 19, 2018 09:10 PM

    I do and I have tried a number of times before my comment for help, but it keeps throwing the error as if I didn't create the CSR from the server. I have tried both servers multiple times, recopied over the keys....etc. Maybe its just a bit glitchy in 6.7. 

     

    -Carl



  • 12.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Aug 19, 2018 09:24 PM

    Have you ever done this successfully on any other version of ClearPass?



  • 13.  RE: download private key on clearpass 6.7

    Posted Aug 19, 2018 09:29 PM
    I have in previous versions, 6.5, 6.6. It just seems to not want to work on this newer version for me. I’ve seeing other post with people having the same issues but no solution post.

    Thanks


  • 14.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Aug 19, 2018 09:57 PM

    I would try to compare the md5 of the certificate and the CSR using openSSL:  https://tecadmin.net/check-certificate-private-key-csr-matcher/

     

     



  • 15.  RE: download private key on clearpass 6.7

    Posted Aug 19, 2018 09:58 PM

    Thanks, doing that now. I suspecting that may be the case. 

     

    -Carl



  • 16.  RE: download private key on clearpass 6.7

    Posted Aug 20, 2018 02:20 AM
      |   view attached

    Don'T know if this fits in here but we do face  also issues with the private key as one of our cluster mebers states Private Key File is not available in the system

    (see attached screenshot)

     

    on the second cluster member ist works just normal. Both CSRs have been created the same way.

     



  • 17.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Aug 20, 2018 02:25 AM

    Please open a TAC case so that this can be pursued:

    http://www.arubanetworks.com/support-services/support-program/contact-support



  • 18.  RE: download private key on clearpass 6.7

    Posted Aug 20, 2018 07:21 AM

    Thanks! I have a call with them today at 11am. 

     

    Carl



  • 19.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Aug 20, 2018 07:09 AM

    Did you generate both the CSRs in the same server?

    ClearPass server only keeps a single private key associated to the latest CSR.  For e.g. Creating a second CSR will override the private key of the first CSR in the system.



  • 20.  RE: download private key on clearpass 6.7

    Posted Aug 20, 2018 07:20 AM

    Thanks for the tip, I actually only generated one as I had planned on using the same cert on both servers for now. I understand that will cause a mismatch due to common name but that is all the client wanted for now. 

     

    Thanks for the tip though! I wasn't aware it would only save one.



  • 21.  RE: download private key on clearpass 6.7

    Posted Oct 05, 2018 01:44 PM

    Just ran into an issue with the customer where we created the CSR like 2 weeks ago and are now just trying to install the certificate using the private key stored in the system.  Clearpass says that 'Private Key File is not available in the system' when we try import.  Because we are using CPPM 6.7.x, there was no downloadable Private Key file.  How do we proceed here?  Customer remembers the Private Key they used when we generated the CSR but that is obviously not helpful.

     

    Thanks in advance.



  • 22.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Oct 05, 2018 02:01 PM
    Generatet a new CSR and get the certificate rekeyed.


  • 23.  RE: download private key on clearpass 6.7

    Posted Oct 24, 2018 10:46 PM

    I created a CSR on my Publisher Clearpass to use on both the Publisher and Subscriber (Standby Publisher).  However, I uploaded the certificate and use saved private key first to the Standby Publisher.  Everything went well.  However, when I tried to upload the certificate and use saved private key to the Publisher I get the error, "Private Key File not available in the system." 

    How would I get the cert uploaded to the Publisher? 



  • 24.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Oct 24, 2018 10:48 PM
    After you upload the signed cert, the key is no longer available to the import process. Export the certificate from the nods and reimport to the publisher.


  • 25.  RE: download private key on clearpass 6.7

    Posted Oct 24, 2018 11:39 PM

    I can't seem to export the cert in 6.7

    Export_Certificate.png

     

     

     



  • 26.  RE: download private key on clearpass 6.7

    EMPLOYEE
    Posted Oct 24, 2018 11:40 PM
    Bottom right.


  • 27.  RE: download private key on clearpass 6.7

    Posted Oct 24, 2018 11:43 PM

    Thanks Cappalli! (I feel like a knucklehead) There it is!



  • 28.  RE: download private key on clearpass 6.7

    Posted Oct 24, 2018 11:57 PM

    Worked like a charm!



  • 29.  RE: download private key on clearpass 6.7

    Posted Aug 21, 2019 07:00 AM

    hello,

    we have a Godaddy certificate on out 6.7 Clearpass.

    the certificate is up for renewal.

    Can i just import renewed certificate OR do i have to generate a NEW CSR?

    CHEERS

    PETE

     

     

     



  • 30.  RE: download private key on clearpass 6.7

    Posted Jan 20, 2020 10:52 AM

    Hey Pete, 

    I know this is an old thread but I just had to renew our "godaddy" clearpass certificate.

     

    This is what I did:

     

    1. Export installed (to expire) certs, this will give you a .p12 file.

    2. Extract private key from .p12 file (you could do this with openssl> openssl pkcs12 -in PKCS12file -out keys_out.txt)

    3. Create fullchain certfile (use the format explained in this post: https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/Unable-to-import-Server-Certificate-on-CPPM/ta-p/186996)

    4. Import new certificate using the "Upload certificate and private key files". Here you should specify the private key file extracted on step 2.

    5. Done!

     

    This worked for me for both radius and https certificates.