Security

 View Only
Expand all | Collapse all

Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

This thread has been viewed 82 times
  • 1.  Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jun 21, 2024 01:26 PM
      |   view attached

    Ever wanted to know how to configure ClearPass Onboard as an EST server to automatically distribute certificates to your network devices?  How about then using those certs to enable RADSEC on the devices?  In this video, I cover what EST is, how to configure it on CX switches and AOS 10 gateways and also how to use the certs for RADSEC to ClearPass.

    Enoy!

    0:00 - Brief intro to EST

    6:29 - EST server configuration on ClearPass Onboard

    20:53 - EST configuration on CX

    30:00 - RADSEC configuration on CX

    43:20 - EST and RADSEC configuration on an AOS 10 Gateway



  • 2.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jun 21, 2024 01:32 PM

    Great content!




  • 3.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jun 23, 2024 10:05 PM

    well done!



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 12:16 PM

    Hi Mike, after using your great Instruction, we get a key-usage mismatch in CX Switch after propper enrollment.  The Onboars CA is an Intermediate. Can you explain why?




  • 5.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 01:57 PM

    is the cx switch TA the root CA ?  




  • 6.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 02:37 PM
    Edited by chulcher Jul 15, 2025 02:37 PM

    You're always going to get that message with how Onboard currently works and the switch expecting/wanting EKU elements that aren't present in the certificate.  The certificate should still be valid for RadSec or supplicant purposes.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 03:00 PM

    Carson summed it up.  What you see is normal, but it's a good thing to point out.  The cert will still work fine for RADSEC.  See my switch output as well:

    radsec                           installed, key-usage mismatch    enroll success    radsec-client




  • 8.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 03:08 PM

    Mike & Carson,

    I don't want to muddy the water but I don't see the same on my end. I am not sure why. It might be a code release thing.




  • 9.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 03:15 PM

    Yeah, when I made that video my switch was on 10.09 and now I'm on 10.15, so there were likely code changes that made that pop.  The cert still works for RADSEC, no issues.




  • 10.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 16, 2025 03:16 AM
    Hi guys, thank you for the clarification.



  • 11.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 03:17 PM

    We just ran a bunch of 6200 at Discover with the uplink configured as an 802.1X supplicant and the certificate enrolled via EST, all of them had that mismatch message but worked just fine.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 12.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 03:21 PM

    What code were they on, Carson?




  • 13.  RE: Instruction - Using ClearPass as an EST server and configuring RADSEC on CX and AOS 10 Gateways

    Posted Jul 15, 2025 03:56 PM

    10.15.1010, I think.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------