Security

 View Only
last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clear Pass Join LDAP

This thread has been viewed 22 times
  • 1.  Clear Pass Join LDAP

    Posted Nov 14, 2022 12:37 PM
    Hi Everyone

    I am trying to joing CLaer pass against LDAP

    I get this error



  • 2.  RE: Clear Pass Join LDAP

    Posted Nov 14, 2022 12:42 PM
    If you are not going to use the administrator account, then I think you may need to specify the domain in the username.  domain\user for example, if you haven't already.


  • 3.  RE: Clear Pass Join LDAP

    EMPLOYEE
    Posted Nov 14, 2022 01:57 PM
    The DNS server ip that the clearpass server is configured with should be a domain controller that can resolve server names for persencetral.es

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 4.  RE: Clear Pass Join LDAP

    Posted Nov 15, 2022 12:52 AM
    Enviado desde mi iPhone




  • 5.  RE: Clear Pass Join LDAP

    Posted Nov 15, 2022 02:15 AM
    Hi

    In addition to the previously mentioned prerequisites, when joining an Active Directory domain the user account utilized for the joining must have correct permissions in the domain.
    The user account must have the domain permission to create computer accounts, and in addition to this, the account must have permission to edit the created computer account.
    Often users have just the right to join the domain and not to edit the computer object. Hence the ClearPass domain join will fail.

    Either the user utilized in the domain join must be granted permission to edit the computer object created or as a domain administrator to perform the join operation.

    One way to achieve the correct permissions in an environment with strict security is to ask a domain administrator to add the computer object first, and grant the user account utilized for the domain join operation permission to edit the computer account.

    ------------------------------
    Best Regards
    Jonas Hammarbäck
    ACCX #1335, ACMP, ACDP, ACNSP, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Clear Pass Join LDAP

    Posted Nov 15, 2022 05:56 AM
    Hi 

    Thanks for your reply .

    That's correct, the user created didn't have AD administrator permissions. When the AD administrators added this user, to the admin group the clear pass made join