Security

 View Only
  • 1.  Mobile Device Wireless Authentication with Clearpass Failure

    Posted Nov 02, 2023 03:54 AM

    Hello,

    We are currently testing Wireless Authentication to our Aruba Instant APs using Clearpass with our mobile devices iOS/Android and have hit a bit of a wall in getting the devices to connect to the corporate network.

    We have issued a user certificate to each device from AD CS Certificate Authority via our Workspace One MDM platform and have confirmed issuance of the cert on each device.

    When we try to connect to the SSID Clearpass reports the following:

    Error Code: 215
    Error Category: Authentication failure
    Error Message: TLS session error
    Alerts for this Request 
    RADIUS EAP-TLS: fatal alert by client - certificate_unknown
    eap-tls: Error in establishing TLS session
    I can confirm that each device has the CA cert onboard and that the CA has issued the user cert to each device.
    Our Clearpass authentication and authorization service is configured as per the Aruba Clearpass Workshop provided by Herman.


  • 2.  RE: Mobile Device Wireless Authentication with Clearpass Failure

    Posted Nov 02, 2023 05:15 AM

    The message: "fatal alert by client - certificate_unknown" means that your client does not trust the ClearPass EAP/RADIUS certificate.

    Make sure that the Root CA that issued the ClearPass EAP certificate is added to your client, and also selected/configured as trusted in the client configuration:

    This screenshot is for TEAP, but similar for other authentication types.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Mobile Device Wireless Authentication with Clearpass Failure

    Posted Nov 02, 2023 06:44 AM

    Hi Herman, Thank you for your response we added the same Root CA to the clearpass server that is also used to issue the user certificates to the mobile devices via our Airwatch MDM platform.

    The Radius certificate on the clearpass server used for EAP was also issued by the same certificate authority so I'm not sure what we are missing in our device config.

    The Radius authentication works fine with our Windows Laptops which have a device certificate issued by the same Root CA.

    Is there anything else I can check ?




  • 4.  RE: Mobile Device Wireless Authentication with Clearpass Failure

    Posted Nov 02, 2023 07:55 AM

    Reading again, the message is 'certificate_unknown', not 'unknown_ca'. It may be the name in 'connect to servers' to not match the RADIUS certificate.

    I would manually configure the client and see if you can make it connect, then duplicate the settings in your Intune.

    Getting this right may take some effort, but in my experience in the end it's something quite simple that you have overlooked. It may be good to do some troubleshooting with someone else, like your partner or Aruba Support as two see more than one.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Mobile Device Wireless Authentication with Clearpass Failure

    Posted Nov 02, 2023 09:31 AM

    Thanks Herman we've managed to fix it, on Airwatch/Workspace One, iOS Wifi Profiles you have to tell it to trust the Radius Server which we added a cert for in the MDM profile.

    Once we filled in the above field everything came together. Thanks again!