Wireless Access

last person joined: 15 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Captive Portal Intermediate Cert

This thread has been viewed 18 times
  • 1.  Captive Portal Intermediate Cert

    Posted Sep 29, 2015 08:25 PM

    I just installed a cert from a trusted CA, but was still getting an untrusted CA warning.  The cert provider instructions included a note saying the intermediate cert should be installed as well.  I looked for how to do that and saw a post that said to just append it to the cert file and upload it to the controller.  The controller took it, but now it's giving "securelogin.arubanetworks.com" for the captive portal - which makes me think I did that wrong.  Doesn't the controller pull the hostname from the cert?

     

    "To correctly install your certificate, it is important to
    configure the server to use the intermediate DigiCertCA.crt
    file in addition to the acme.company.crt"



  • 2.  RE: Captive Portal Intermediate Cert

    EMPLOYEE
    Posted Sep 29, 2015 08:27 PM

    Did you set that certificate as teh captive portal cert?



  • 3.  RE: Captive Portal Intermediate Cert

    Posted Sep 29, 2015 08:30 PM

    Yep!  And after I made the change to append the intermediate cert, I went and made sure the new one I uploaded with the intermediate cert was selected.

     

    The file is a .crt file, pem format and it looks like this:

     

    -----BEGIN CERTIFICATE-----
    blahblahblah server cert
    -----END CERTIFICATE-----
    -----BEGIN CERTIFICATE-----
    blahblahblah intermediate cert
    -----END CERTIFICATE-----

     

    When I view the cert in the controller, I see the correct hostname and details of the cert.



  • 4.  RE: Captive Portal Intermediate Cert
    Best Answer

    EMPLOYEE
    Posted Sep 29, 2015 08:33 PM
    Try nesting all 3 certificates into the server cert file (server, int, root). You’ll also want to import the intermediate and root individually to the controller.


  • 5.  RE: Captive Portal Intermediate Cert

    Posted Sep 29, 2015 08:43 PM

    I hadn't done this yet.  When I posted the screen shot, I didn't see this reply.

     

    When you say nest them, you mean all within the same file, correct?  And when you say to import the intermediate and CA, would I import them as trusted CAs?



  • 6.  RE: Captive Portal Intermediate Cert

    EMPLOYEE
    Posted Sep 29, 2015 08:58 PM
    Correct, combine them all into the same file in the order of server cert, int, root and import as the server cert.

    Then import the intermediate as type Intermediate CA and the root as type Trusted CA.


  • 7.  RE: Captive Portal Intermediate Cert

    Posted Sep 29, 2015 09:02 PM

    Done.  I'll have to wait til tomorrow for the user to  be on site again to test.

     

    I'll update the thread tomorrow.

     

    Thanks!

     

     



  • 8.  RE: Captive Portal Intermediate Cert

    Posted Sep 30, 2015 01:02 PM

    I just got confirmation from the user that this worked.  No cert warnings, and correct CP URL.

     

    Only thing though - is it officially necessary to have the whole chain in the cert AND upload the intermediate and CA to the controller separately?  Or is that just for good measure?

     

    Thanks!



  • 9.  RE: Captive Portal Intermediate Cert

    EMPLOYEE
    Posted Sep 30, 2015 01:18 PM
    It's best practice these days as some browsers are fine and others bark.


  • 10.  RE: Captive Portal Intermediate Cert

    Posted Sep 30, 2015 01:59 PM

    Okay, that makes sense.  I will put notes in my design log to make sure that's how I configure certs that require reference to intermediate CA's.

     

    Thanks!



  • 11.  RE: Captive Portal Intermediate Cert

    Posted Sep 29, 2015 08:37 PM

    This is the error I'm seeing now.  The white empty space is the hostname of our controller that the cert is for.

     

    screenshot99.png



  • 12.  RE: Captive Portal Intermediate Cert

    EMPLOYEE
    Posted Sep 29, 2015 08:38 PM
    Do you have multiple controllers?


  • 13.  RE: Captive Portal Intermediate Cert

    Posted Sep 29, 2015 08:42 PM

    There is just one physical controller (7005) in this location and it's not tied to our other Aruba controllers in any way (local/master, etc.).