Security

 View Only
last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

SSL Cert Help

This thread has been viewed 27 times
  • 1.  SSL Cert Help

    Posted Aug 15, 2022 01:46 PM
    Been through a lot of threads but nothing has helped yet so I have to ask.
    I used this:
    Airheads Community

    And generated the pem, then converted to a p12 for pc.
    Copied pem to aruba s3500.
    set it as switch cert and captive portal cert.
    Imported p12 on pc.

    Restarted Chrome but I still get cert not valid.
    Originally I got NET::ERR_CERT_COMMON_NAME_INVALID because I had an underscore in the name (aruba_s3500).
    So I redid the whole process and changed the name to arubas3500, now I just get cert not valid.

    Anyone have any ideas what to try next?



  • 2.  RE: SSL Cert Help

    EMPLOYEE
    Posted Aug 17, 2022 05:15 AM
    You will need to get a public signed certificate. The article you refer to is about a self-signed certificate and mentions that you need to get a public certificate to avoid certificate warnings:
    Note: Using a self signed certificate for captive portal authentication can cause browsers to display a certificate warning. Hence it is recommended to have a publicly signed certificate for captive portal authentication. If there are multiple controllers, we can either install a single publicly signed certificate on all the controllers or go for a wild card certificate.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: SSL Cert Help

    Posted Aug 17, 2022 01:25 PM
    Thanks. Should've mentioned I only want a self signed but I thought referencing that article would hint to that.
    Actually got it fixed, went back to my tried and true, create the cert in pfSense.

    On another note, does anyone have a problem using Chrome with Aruba hardware?
    I'm using an S3500 specifically and anytime I try to click on what should be a text entry box, the box doesn't stay open. (ie vlan ip, port profiles, any entry box)
    I found a workaround by keeping the left mouse button clicked on the entry and when the box appears, right click while still holding the left. This allows the box to remain open.
    Just wondering if there's a setting in Chrome I can change?
    Works fine in Firefox.


  • 4.  RE: SSL Cert Help

    EMPLOYEE
    Posted Aug 18, 2022 07:39 AM
    The S3500 is end-of-support for some time, and I know that at least older firmware versions had issues like these when connected to from a modern browser. You may try to upgrade to the very latest firmware for the S3500 if you are not running that.

    I have a 'Portable' browser with an old version of Firefox (one that doesn't need to be installed) in case I run into issues with equipment from multiple vendors.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------