Security

 View Only
  • 1.  Using Onboard to distribute Device Certificates

    Posted 5 hours ago

    Hello,

    I am using Aruba Network Onboard together with Aruba Central NAC and Microsoft Entra ID for certificate-based authentication. We have successfully deployed user certificates and users can authenticate to the network using EAP-TLS.

    However, we are experiencing an issue where network connectivity is lost when a user signs out of Windows. Locking the workstation does not cause any problems, but signing out terminates network access until a user logs in again.

    Our goal is to have devices remain authenticated to the network even when no user session is active, so that remote management and remote access tools continue to function.

    We would prefer to use certificate-based authentication only and avoid MAC-based authentication.

    What is the recommended approach with Aruba Network Onboard to deploy machine/device certificates instead of user certificates? or is there another recommended method to achieve persistent device authentication?



  • 2.  RE: Using Onboard to distribute Device Certificates

    Posted 5 hours ago

    ClearPass Onboard i is user centric, I think you are only able to issue user certificate with the built in Onboard enrollment.

    Possibly you can enable SCEP in ClearPass and enroll the certificates this way for the computer account. Another possible way could be to use the CA function in Central NAC to enroll for machine certificates.

    One important thing to remember is that you also need to reconfigure your 802.1x profiles on the computers, and change to "User or computer authentication" otherwise Windows will not change the authentication to the machine certificate when there are no user logged on.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------