Security

 View Only
  • 1.  NEW PHONES GIVING CA ERRORS

    Posted Jul 19, 2023 12:06 PM
      |   view attached

    Hello,

    We have a working setup that all of my certificates are valid and my previous clients can authenticate without a problem in my Aruba Wireless Network. But when clients get new mobile phone it's giving an error in the attachments. I don't know what changed in the client side in brand new phones. Any ideas?



  • 2.  RE: NEW PHONES GIVING CA ERRORS

    Posted Jul 20, 2023 03:36 AM

    fatal by client - unknown_ca is clear: Your client does not know/trust the root CA that signed the RADIUS/EAP certificate on ClearPass.

    What type of RADIUS/EAP certificate have you deployed on ClearPass, as in signed by which CA?

    How do you provision your phones for network access? Note that in older Android versions you could ignore the server certificate (which allowed attacks on user credentials), in more recent versions you can no longer ignore the server certifcate for better security. That has as a result that these devices would need more configuration, and tooling for that would be strongly recommended. Tooling could be ClearPass Onboard for non-managed devices, or a Mobile Device Management for managed devices.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: NEW PHONES GIVING CA ERRORS

    Posted Jul 20, 2023 04:36 AM

    Hello,

    Thank you for your answer, we have Radius/ EAP certificate that is signed with Company's Certificate Authority. It's local certificate with the same domain as Clearpass.  For new clients that can not associate with Wireless which type of certififcate we need to use?   




  • 4.  RE: NEW PHONES GIVING CA ERRORS

    Posted Jul 20, 2023 04:56 AM

    An EAP certificate signed by a private CA (Company CA) should work fine, and is what I would recommend.

    However in order for modern Android clients to trust that certificate, you would need to install the Company CA (that signed the EAP certificate) in your client before you can connect to the network, and you would need to trust that. Having an automation tool (mentioned in my previous response) would make that more user friendly, but to verify that is indeed the issue I would configure it manually first.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: NEW PHONES GIVING CA ERRORS

    Posted Jul 20, 2023 05:47 AM

    Yes the EAP Certificate is  signed by a private CA. We manually added the certificate to the client phone but we still get EAP Errors in the below.

    But we have configured the below methods and client is sending EAP as a method.
    We also tried to change the order of the methods but it didn't worked.



  • 6.  RE: NEW PHONES GIVING CA ERRORS

    Posted Jul 20, 2023 07:09 AM

    Just add the methods that you use, remove everything else. If you use EAP-TLS, remove everything else. If you use PEAP-MSCHAPv2 (deprecated), just add [EAP MSCHAPv2]. If you do both, just add those two. For sure don't put MAC Auth methods in EAP authentication services.

    How did you configure the client? That is probably where the problem is...



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------