Wireless Access

last person joined: 5 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Clearpass Radius Server Certificate

This thread has been viewed 13 times
  • 1.  Clearpass Radius Server Certificate

    Posted Oct 29, 2018 08:17 AM

    Hey Guys,

    I've created a private signed radius server certificate for my Clearpass Cluster for 802.1x authentication. When I try to upload this certificate I just get a "success" message but the certificate is not getting uploaded or updated. Its still shows the default certificate.

    Do I have to restart the server to make this change active? 

     

    My Cluster contains two nodes and is running version  6.7.3.106273 

    Thanks and best regards!

     



  • 2.  RE: Clearpass Radius Server Certificate

    Posted Oct 29, 2018 08:43 AM

    Did you creat a CSR and upload or just created a certificate and uploaded?

     

    In the dropdown menu on the certificate page in Clearpass have you selected RADIUS and not HTTP certificate?

     

    Regards

    Philip



  • 3.  RE: Clearpass Radius Server Certificate

    Posted Oct 29, 2018 08:50 AM

    Hey Philip,

    thanks for your reply.

    I've created a CSR on an external machine with OpenSSL and then signed it with my internal pki. Yes, when I try to upload I choose radius certificate and not http.

    The RootCA certificate is also imported and enabled. 

    Best regards! 



  • 4.  RE: Clearpass Radius Server Certificate

    EMPLOYEE
    Posted Oct 29, 2018 09:55 AM

    Hi,

     

    Create CSR on your CPPM server and get it singed with your internal PKI or external CA, once you get singed certificate, import the certificate to CPPM server and make sure you remeber private key password, which you entered during CSR generation.

     

    communitry.PNG



  • 5.  RE: Clearpass Radius Server Certificate

    Posted Oct 29, 2018 11:10 AM

    Hello Pavan,

    thanks for your reply.

    Unfortunately, this didn't solve the issue. Like you recommended I've created the csr directly on Clearpass and signed it with our internal pki.

    The following error message is now displayed to me:

    "Certificate File is not suitable for web server authentication" 

     

    Edit: The certificate type is X.509 Certificate with .crt ending

     

    Best regards!

     



  • 6.  RE: Clearpass Radius Server Certificate

    EMPLOYEE
    Posted Oct 29, 2018 11:20 AM
    Does your certificate have the Server Authentication EKU?


  • 7.  RE: Clearpass Radius Server Certificate

    Posted Oct 29, 2018 11:36 AM

    Hello cappalli,

    thanks for your reply.

    I assume its a setting which must be set while creating the cert? 

    I will talk to the responsible guys to find out if its there.

     

    Best regards

     



  • 8.  RE: Clearpass Radius Server Certificate
    Best Answer

    Posted Oct 31, 2018 06:07 AM

    Hey Guys,

    I was able to fix that issue.

    Unfortunately, the certificate was created with a wrong template internally.

    Thanks for your support.

    Best regards!