Security

 View Only
  • 1.  Clearpass HTTPS Cert

    Posted Dec 16, 2024 12:56 AM

    Hi Folks,

    I upgraded Clearpass cluster from 6.10.8 to 6.11.10 last week with everything working except public HTTPS cert used for Guest Portal. 

    HTTPS cert was exported from 6.10.8 with .p12 format and imported into 6.11.8 (Same physical node) with no error.  However, Guest portal shows this cert is not trusted from wifi client end.  Not sure if anyone else is experiencing the same issue?  Will new GSR and new cert resolve this ? 

    Regards

    Charles 



  • 2.  RE: Clearpass HTTPS Cert

    Posted Dec 16, 2024 10:36 AM

    Can you share some screenshots of the error and maybe the certificate store?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Clearpass HTTPS Cert

    Posted Dec 19, 2024 05:29 AM

    Do you have an RSA or ECC certificate? If you imported RSA, make sure that the HTTPS(ECC) certificate is disabled. If you imported an ECC certificate, make sure the HTTPS(RSA) is disabled.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: Clearpass HTTPS Cert

    Posted Dec 20, 2024 07:09 AM

    Hi Chulcher & Herman,

    Thanks for kind reply and sorry for my late response. Below is more information regarding the issue I am experiencing:

    1. This public HTTPS (RSA) certificate is signed by DigiCert. There are no errors in the Certificate Store, and the root CA trust chain is in place without issues.

    2. In this case, I cannot disable the HTTPS (ECC) certificate (self-signed) as it is used by the CPPM Cluster. Interestingly, CPPM (6.11.10) seems to prefers the HTTPS self-signed ECC certificate over the HTTPS RSA certificate (DigiCert-signed) when selecting the HTTPS certificate for the cluster. Both types of certificates were enabled during the clustering setup between the two CPPM nodes, and obviioutly CPPM chose the HTTPS ECC certificate for some reason. Not sure if this is expected behaviour..

    3. On the client-side PC, I confimed the HTTPS (RSA) public certificate is being used for the Guest Portal, yet it still appears as untrusted for some reason.

    Thanks 

    Charles 




  • 5.  RE: Clearpass HTTPS Cert

    Posted Dec 20, 2024 08:48 AM

    Most modern clients prefer ECC over RSA if both are offered. Not sure what you refer to for the clustering... the database certificate is used for the database synchronization and needs to have the IP address as DNS-SAN, but is separate from HTTPS.

    Because you can't really control which certificate a client will prefer, you should either have both RSA and ECC certificate, or disable the one not in use.

    I normally check installed certificates and chains with openssl (openssl s_client --showcerts -connect www.arubanetworks.com:443), but DigiCert seems to offer a Windows tool as well (didn't work for me, but maybe because I don't have DigiCert certificate).



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: Clearpass HTTPS Cert

    Posted Dec 21, 2024 04:35 AM

    Hi Hernam,

    The process of establishing cluster between 2 CPPM nodes, HTTPS certs validation is also required. In my case, CCPM subscriber added publisher's HTTPS self signed ECC cert into its trust list.




  • 7.  RE: Clearpass HTTPS Cert

    Posted Dec 23, 2024 02:58 AM

    I've not seen issues after cluster is formed, but I don't change certificates regularly. Have you tried to disable the ECC certificate, and did that break the cluster? Please work with TAC/Support as it's much easier to find the best solution when you have access to the system.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------