Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Radius/EAP Server certificates

This thread has been viewed 21 times
  • 1.  Radius/EAP Server certificates

    Posted Dec 02, 2022 11:44 AM
    I Have a Clearpass deployment that consists of a Publisher and One subscriber.
    For 802.1x authentications, is it possible to have both the Publisher and the Subscriber use the same Radius/EAP server certificate?

    This issue with using two certs is that I have users that travel between sites where some sites have the Publisher as the Radius Server and other sites have the Subscriber. This results in the user constantly being prompted to trust the certificate.  If I could use a certificate that was common to both servers, this would not be an issue.

    I have explored the option of using a service certificate but I would have to configure over 150 services to use that certificate and then reconfigure annually as the certificate expires and has to be re-issued.

    Thanks in advance for any advice.

    ------------------------------
    Senior Network Analyst
    Ottawa Carleton District School Board
    Ottawa ON
    Canada
    ------------------------------


  • 2.  RE: Radius/EAP Server certificates
    Best Answer

    Posted Dec 02, 2022 12:26 PM
    Yes just make sure the hostname of both nodes are in the SANs field.

    What you describe though means the client does not trust the CA that signed your ClearPass certificate.  What is your ClearPass certificate?  Self-signed?  Private CA? Public CA? 

    Also why do you have 150 different services?  What is your use-case?


  • 3.  RE: Radius/EAP Server certificates

    MVP EXPERT
    Posted Dec 03, 2022 10:35 AM
    I use the same radius cert on all cluster nodes and it’s different to the cert used for https so all you need to do is make sure the clients recognise the CA that issued the radius cert
    I use another cert for https access and in that case make sure all cluster nodes fqdns are in the SaN fields
    A

    Sent from my iPhone




  • 4.  RE: Radius/EAP Server certificates

    Posted Dec 05, 2022 07:27 AM
    Thanks for this info.

    Yeah, the 150 services is a bit of a chore but I have to have them. One for each Site / IAP Cluster. It all comes down to the accounting proxy target which is unique to each IAP Cluster.

    ------------------------------
    Senior Network Analyst
    Ottawa Carleton District School Board
    Ottawa ON
    Canada
    ------------------------------



  • 5.  RE: Radius/EAP Server certificates

    EMPLOYEE
    Posted Dec 04, 2022 05:45 PM
    Hi Tpelley,

    Radius certificates don't require an FQDN that can be resolved by DNS (assuming your Radius certificate is separate to the HTTPS certificate). So it is fine to have a single certificate, e.g. clearpass.yourdomain.co, which can be installed on both ClearPass nodes. 

    Make sure that this certificate is signed by a Certificate Authority (CA) and not self-signed. Both ClearPass servers will need to have the CA certificates in the trust store in order to install the certificate. The clients authenticating via ClearPass will also ideally have this CA certificate installed and marked as trusted. You are best to configure this trust along with identity (name) of ClearPass within the supplicant configuration so that users aren't prompted regarding trust. This might be done in Group Policy or an MDM profile.

    Good luck.


  • 6.  RE: Radius/EAP Server certificates

    Posted Dec 05, 2022 07:28 AM
    Thank You

    ------------------------------
    Senior Network Analyst
    Ottawa Carleton District School Board
    Ottawa ON
    Canada
    ------------------------------