Configuring General Provisioning Settings

To configure basic provisioning settings, go to Onboard > Deployment and Provisioning > Provisioning Settings. The Provisioning Settings list opens. Either click the Edit link for a configuration set in the list, or click the Create new provisioning settings link to open the Provisioning Settings configuration form. This form has several tabs. The first tab that opens is the General tab, and is used to specify basic information about Onboard provisioning.

Figure 1  The General Tab, Device Provisioning Settings Form

Provisioning Settings, General Tab, Basic Information Area

Field

Description

Name

(Required) Name of this configuration set. This name is used internally to identify this set of Onboard settings for the network administrator. This value is never displayed to the user during device provisioning.

Description

Brief description of this configuration set. This description is used internally to identify this set of Onboard settings for the network administrator. This value is never displayed to the user during device provisioning.

Organization

(Required) The name of your organization. This is displayed to the user during the device provisioning process.

Figure 2  The Provisioning Settings Form, General Tab, Identity and Authorization Areas

 

If you use Active Directory Microsoft Active Directory. The directory server that stores information about a variety of things, such as organizations, sites, systems, users, shares, and other network objects or components. It also provides authentication and authorization mechanisms, and a framework within which related services can be deployed. Certificate Services (ADCS), you might need to add your ADCS certificate to the Trust List. When connecting to ADCS to issue an Onboard certificate, the server certificate is verified against the ClearPass Trust List.

Provisioning Settings Form, General Tab, Identity Area

Field

Description

Certificate Authority

(Required) Specifies the Certificate Authority (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.) used to sign profiles and messages (see Creating a New Certificate Authority). Options include:

Local Certificate Authority

SCEP-RA

Signer

(Required) Specifies the source to use for signing TLS Transport Layer Security. TLS is a cryptographic protocol that provides communication security over the Internet. TLS encrypts the segments of network connections above the Transport Layer by using asymmetric cryptography for key exchange, symmetric encryption for privacy, and message authentication codes for message integrity. client certificates. Options include:

Onboard Certificate Authority

Active Directory Certificate Services — The ADCS URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. and ADCS Template rows are added to the form. ACDS can only be used with certificate-based authentication; it cannot be used with username/password authentication.

TLS Certificate Authority

(Required) Specifies the Certificate Authority (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.) used to use to sign TLS Transport Layer Security. TLS is a cryptographic protocol that provides communication security over the Internet. TLS encrypts the segments of network connections above the Transport Layer by using asymmetric cryptography for key exchange, symmetric encryption for privacy, and message authentication codes for message integrity. client certificates. Options include:

Local Certificate Authority

SCEP-RA

ADCS URL

(Required) If Active Directory Microsoft Active Directory. The directory server that stores information about a variety of things, such as organizations, sites, systems, users, shares, and other network objects or components. It also provides authentication and authorization mechanisms, and a framework within which related services can be deployed. Certificate Services was chosen in the Signer field, enter the URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. of the ADCS server in the field. This URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. should be the Web interface for ADCS, and is typically http://<server>/certsrv/.

ADCS Template

(Required) If Active Directory Microsoft Active Directory. The directory server that stores information about a variety of things, such as organizations, sites, systems, users, shares, and other network objects or components. It also provides authentication and authorization mechanisms, and a framework within which related services can be deployed. Certificate Services was chosen in the Signer field, enter the name of the template to use when requesting the certificate. If the name is not known, you can use the default name of "user".

Key Type

(Required) Specifies the type of private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. to use when issuing a new certificate. Options include:

1024-bit RSA – created by server: Lower security. Not available in FIPS Federal Information Processing Standards. FIPS refers to a set of standards that describe document processing, encryption algorithms, and other information technology standards for use within non-military government agencies, and by government contractors and vendors who work with these agencies. mode.

1024-bit RSA – created by device: Lower security. Uses SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. to provision the EAP-TLS EAP–Transport Layer Security. EAP-TLS is a certificate-based authentication method supporting mutual authentication, integrity-protected ciphersuite negotiation and key exchange between two endpoints. See RFC 5216. certificate. Not available in FIPS Federal Information Processing Standards. FIPS refers to a set of standards that describe document processing, encryption algorithms, and other information technology standards for use within non-military government agencies, and by government contractors and vendors who work with these agencies. mode.

2048-bit RSA – created by server: Recommended for general use.

2048-bit RSA – created by device: (Default) Recommended for general use. Uses SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. to provision the EAP-TLS EAP–Transport Layer Security. EAP-TLS is a certificate-based authentication method supporting mutual authentication, integrity-protected ciphersuite negotiation and key exchange between two endpoints. See RFC 5216. certificate.

4096-bit RSA – created by server: Higher security.

X9.62/SECG curve over a 256 bit prime field - created by server

NIST/SECG curve over a 384 bit prime field - created by server

See Note below this table.

Unique Device Credentials

(Required) If selected, includes the username as a prefix in the device's PEAP Protected Extensible Authentication Protocol. PEAP is a type of EAP communication that addresses security issues associated with clear text EAP transmissions by creating a secure channel encrypted and protected by TLS. credentials.

 

Using a private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. containing more bits will increase security, but will also increase the processing time required to create the certificate and authenticate the device. The additional processing required will also affect the battery life of a mobile device. It is recommended to use the smallest private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. size that is feasible for your organization. The “created by device” options use SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates. to provision the EAP-TLS EAP–Transport Layer Security. EAP-TLS is a certificate-based authentication method supporting mutual authentication, integrity-protected ciphersuite negotiation and key exchange between two endpoints. See RFC 5216. device certificate, so the private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. is known only to the device rather than also known by the user. When a “created by device” option is selected, the generated key is used instead of a username/password authentication defined in Network Settings.

Provisioning Settings Form, General Tab, Authorization Area

Field

Description

Authorization Method

Specifies the authorization method for devices. Options include:

App Auth – check using Aruba Application Authentication

RADIUS – check using a RADIUS request

Use SSO

If selected, users will be required to authenticate using Single Sign-On (SSO Single Sign-On. SSO is an access-control property that allows the users to log in once to access multiple related, but independent applications or systems to which they have privileges. The process authenticates the user across all allowed resources during their session, eliminating additional login prompts.).
(SSO Single Sign-On. SSO is an access-control property that allows the users to log in once to access multiple related, but independent applications or systems to which they have privileges. The process authenticates the user across all allowed resources during their session, eliminating additional login prompts. support is enabled at Policy Manager > Configuration > Identity > Single Sign-On.)

Configuration Profile

(Required) Specifies the configuration profile to provision to devices. All configuration profiles that have been created are included in this list. A configuration profile specifies an application set, Exchange ActiveSync Mobile data synchronization app developed by Microsoft that allows a mobile device to be synchronized with either a desktop or a server running compatible software products. settings, network settings, passcode policy, VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two., and other settings. For more information, see Onboard Configuration.

Maximum Devices

(Required) Enter a number to specify the maximum number of devices that each user may provision. To be enrolled, a device must have a currently valid certificate, and its status set to Allowed (at Onboard > Management and Control > View by Device).

Figure 3  The Provisioning Settings Form, General Tab, Actions Area

Provisioning Settings Form, General Tab, Actions Area

Field

Description

Certificate Expiry

Specifies that users will receive an email notification when their device's network credentials are about to expire. The form expands to include options for configuring the notification email.

Send Email Notification

(Required) Specifies when to send the notification email. Options include:

1 week prior to expiration

2 weeks prior to expiration

3 weeks prior to expiration

4 weeks prior to expiration

If Email is Unknown

(Required) Specifies action to take if the user's email address is not recorded with the certificate. Options include:

Do not send any message

Send a message to a fixed email address

Send a message to username@domain

Unknown Address

Address to use when no email address is known for the user.

Unknown Domain

Domain to append to the username to form an email address.

Subject Line

(Required) Subject line for the notification email.

Email Message

(Required) Plain text or HTML print template to use when generating the email message. Options include:

Account List

Certificate Expiry

Download Receipt

GuestManager Receipt

One account per page

SMS Receipt

Sponsorship Confirmation

Two-column scratch cards

Email Skin

(Required) Format to use for email receipts. Options include:

Use the default skin

No skin – Plain text only

No skin – HTML only

No skin – Native receipt format

Aruba ClearPass Skin

Blank Skin

ClearPass Guest Skin

Custom Skin 1

Custom Skin 2

Galleria Skin

Galleria Skin 2

Send Copies

(Required) Specifies how to send copies to the recipients in the Copies To list. Options include:

Do not send copies

Always send using "cc:"

Always send using "Bcc:"

Revoke Inactive

If selected, certificates for devices are revoked after a specified amount of time that the device is not seen on the network.

You must have an Insight primary node enabled with an appropriate data retention period configured.

Inactivity Period

(Required) Number of days that a device should be absent from the network before its certificate is revoked.

Delete Duplicates

If selected, old certificates from previous enrollments are automatically deleted.

Deletion Delay

(Required) Number of days that should pass after re-enrollment before old (duplicate) certificates are deleted.

Provisioning Address

Hostname or IP address to use for device provisioning.

Click Next to proceed to the next tab, or Save Changes to complete your edits.

To return to the list of links to all Provisioning Settings tabs, see About Configuring Provisioning Settings .