Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

IAP-225 Virtual Controller SSL Certificate

This thread has been viewed 10 times
  • 1.  IAP-225 Virtual Controller SSL Certificate

    Posted Oct 03, 2016 05:03 PM

    Hi All!

     

    I'm using a set of Aruba IAP-225 Access Points with a Virtual Controller.
    My Network has  WPA2-Enterprise 802.1X encryption.

     

    Recently I saw information online  that the certificate shipped with the device was compromised and is not safe to use.
    I wanted to change it with my own one and encountered a problem.


    The WebUI only let's me upload the certificate but not manage them.
    The tutorial says that using the 'clear-cert' CLI command I can erase certificates, but it only let's me delete the ones I uploaded myself not the ones that were put there by the manufacturer.

    Am I missing something?
    Is there a way to change the default certificate that is used for WPA2-Enterprise encryption?



  • 2.  RE: IAP-225 Virtual Controller SSL Certificate

    EMPLOYEE
    Posted Oct 03, 2016 05:05 PM
    You set the usage when you upload the certificate. There is a drop down box.


  • 3.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 03, 2016 05:23 PM
      |   view attached

    I get this error if I try to chose anything other than CA.



  • 4.  RE: IAP-225 Virtual Controller SSL Certificate

    EMPLOYEE
    Posted Oct 03, 2016 05:49 PM

    Is there a radius server in your environment?



  • 5.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 04, 2016 07:52 AM

    No, I use ldap integration directly from the Virtual Controller.



  • 6.  RE: IAP-225 Virtual Controller SSL Certificate

    EMPLOYEE
    Posted Oct 04, 2016 08:32 AM

    Where did you obtain your certificate?

     

    What format is it in?



  • 7.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 04, 2016 10:09 AM

    Bought it on GoDaddy.



  • 8.  RE: IAP-225 Virtual Controller SSL Certificate

    EMPLOYEE
    Posted Oct 04, 2016 10:13 AM
    Did you combine the private and public keys with the cert chain in a .pem
    file?


  • 9.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 04, 2016 10:43 AM

    Hello All,

     

    Ok so I've tried all the instructions I could find on using Openssl to create a self signed certificate to use temporarily until we purchase our new certificate. When I try uploading it says wrong format. Any suggestions before I contact support?



  • 10.  RE: IAP-225 Virtual Controller SSL Certificate



  • 11.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 04, 2016 11:04 AM

    Yes, I did. There were also 2 other instructions I followed as well with the same result. I combined the keys and certs as instructed as well. Does this maybe have to be imported through CLI instead of the Virtual Controller GUI?



  • 12.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 04, 2016 11:07 AM

    Yes, I tried to upload a combined *.pem file.



  • 13.  RE: IAP-225 Virtual Controller SSL Certificate
    Best Answer

    Posted Oct 05, 2016 06:12 AM

    Make sure you output your crt and key in PEM format.

     

    1. use openssl to convert the crt file to a pem file
      openssl x509 -outform PEM -in server.crt -out server.crt.pem
    2. use openssl to convert the key file to a pem file, keep in mind that you change x509 for rsa
      openssl rsa -outform PEM -in server.key -out server.key.pem
    3. also convert any CA you want to incorporate into the new pem file, just use the first example at step 1
    4. now paste all the content from the pem files into 1 combined file
    5. now upload the new pem file to the (virtual)controller
    6. if all went well the controller will restart it's internal webserver and you can now connect to the CN of your certificate on port 4343


  • 14.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 05, 2016 09:39 AM

    So, I am trying to create a self-signed certificate. So I've tried strating up a linux box with Openssl. I setup a CA authority using instructions https://jamielinux.com/docs/openssl-certificate-authority/introduction.html. I created according to the instructions. Then I followed https://community.arubanetworks.com/t5/Controller-less-WLANs/ArubaOS-Default-Certificate-Revocation-FAQ-Instant/ta-p/275814. Successfully created a *.pem file with the private key, public cert and the intermediate root ca. I upload and get a message that the format is incorrect. The instructions to create a self-signed cert doesnt seem to work either located. http://community.arubanetworks.com/t5/Controller-Based-WLANs/How-do-I-generate-an-OpenSSL-self-signed-certificate-in-pem/ta-p/177148 and I cannot find a guide or instructions that are clear and simple to follow that works. It is worthy to note that we are not using clearpass. We are using a dell switch with virtual controller.



  • 15.  RE: IAP-225 Virtual Controller SSL Certificate

    Posted Oct 06, 2016 08:45 AM

    Actually this helped.
    I'm gonna see if I did everything correctly with the cerftificate I bought.