Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CA requirements for rolling out WPA3-Enterprise

This thread has been viewed 13 times
  • 1.  CA requirements for rolling out WPA3-Enterprise

    MVP EXPERT
    Posted Mar 30, 2023 05:06 AM

    A while back i set up a  test wpa3-enterprise net here using  clearpass as the pki.

    It was a while back and  sadly didn't make any notes but seem to remember i had to make changes to the CA cert size  before I managed to get a client to connect to a wpa3 net

    Can someone remind me how our  CA needs to be configured to support  eap-tls on a wpa3-enterprise network

    A



  • 2.  RE: CA requirements for rolling out WPA3-Enterprise

    Posted Mar 30, 2023 10:16 AM

    I've got clients running WPA3 Enterprise using EAP-TLS and I'm not aware of them having to make CA specific changes.  These customers are all using Microsoft AD CA.




  • 3.  RE: CA requirements for rolling out WPA3-Enterprise

    MVP EXPERT
    Posted Mar 30, 2023 10:47 AM
    Ah! Ok. I was using the ClearPass CA ..I’ll try and remember what I did :-(




  • 4.  RE: CA requirements for rolling out WPA3-Enterprise

    EMPLOYEE
    Posted Apr 03, 2023 10:00 AM

    You will need to set the key size to 4096 bits RSA or 384 bit ECC or higher. Check here for more info.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------