Security

 View Only
last person joined: 6 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass integration with Azure/Intune PKI

This thread has been viewed 27 times
  • 1.  Clearpass integration with Azure/Intune PKI

    Posted 14 days ago

    Hello,

    One of our customers will be migrating to the Azure/Intune PKI environment. We have been asked if its possible to create a cert for the Clearpass Server from the Azure/Intune PKI. Has anyone managed to get this to work previously?

    Thank you in advance for any contribution. 

    Kind regards



  • 2.  RE: Clearpass integration with Azure/Intune PKI

    EMPLOYEE
    Posted 14 days ago

    Talking about Microsoft Cloud PKI for Microsoft Intune?  That appears to be a PKI setup strictly for managed devices.  Why would ClearPass need a certificate from the Cloud PKI?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Clearpass integration with Azure/Intune PKI

    Posted 13 days ago

    Hi,

    That is because this is the Root CA within our customer's deployment. We just need a valid certificate on Clearpass and unfortunately Cloud PKI is what would be the issuer. 




  • 4.  RE: Clearpass integration with Azure/Intune PKI

    EMPLOYEE
    Posted 13 days ago

    I'm not seeing any indication that such is possible.  They'll need to use a separate PKI to issue the certificate for ClearPass and then use Intune to make sure that the client devices have the correct trust anchors in place.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Clearpass integration with Azure/Intune PKI

    Posted 13 days ago

    Either buy a certificate from a public CA, or configure ClearPass as a Root CA and issue the needed server certificate from this CA.

    Server certificates does not need an Onboard license as the client certificates do



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Clearpass integration with Azure/Intune PKI

    EMPLOYEE
    Posted 13 days ago

    Every certificate issued using an Onboard CA requires Onboard licensing to be in place.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Clearpass integration with Azure/Intune PKI

    EMPLOYEE
    Posted 13 days ago

    To my knowledge, only client/device certificates (that have not expired or are revoked), count as one Onboard license per user.

    From the documentation: "Onboard license usage is computed based on the number of users with Onboard-generated device certificates."

    A server certificate is not supposed to count against Onboard licenses in my experience.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: Clearpass integration with Azure/Intune PKI

    EMPLOYEE
    Posted 12 days ago

    You might want to have a discussion with Bryan.  I've asked this question in the past and received the answer I shared: all certificates issued by ClearPass require an associated Onboard license.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 9.  RE: Clearpass integration with Azure/Intune PKI

    MVP
    Posted 12 days ago

    I believe the cloud PKI is a relatively new offering. I have also not heard of anyone trying it.

    https://learn.microsoft.com/en-us/mem/intune/protect/microsoft-cloud-pki-overview



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------