Certificate Usage Profile
Certificate usage profiles in HPE Aruba Networking Central define how digital certificates are utilized within networking solutions. These profiles enhance security by ensuring secure communication, authenticating users, and managing access control. Understanding these profiles is essential for effective network management and security compliance.
Creating a Certificate Usage Profile
To create an Certificate Usage Profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Certificate Usage Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Groups level, complete the following steps before step 4:
- Select Site Collections, Sites, Devices, or Device Groups in the left navigation menu.
- Select a site collection, site, device, or device group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Security card, click the second radio button, and then click Certificate Usage.
If you create the profile in the Library, then click the second radio button on the Security card, and then click Certificate Usage.
Alternatively, you can complete the following steps:-
On the Security card, click Manage.
-
On the Certificate Usage card, click Manage.
The Certificate Usage list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed
-
Configure the parameters as described in the following table.
Table 1: Certificate Usage Profile Parameters
Parameter
Description
Create as a local profile
Select this option if you want to configure this profile as local.
The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.
Name
Enter the name of the Certificate Usage profile.
Description
Enter a brief description for the Certificate Usage profile.
Device Type
Select a device from the following:
- Access Point
- Gateway
Access Point Parameters
Authentication Server CA
Select an authentication server CA from the drop-down list to verify the identity of a client.
Authentication Server Cert
Select an authentication server certificate from the drop-down list.
Captive Portal Server Cert
Select a captive portal server certificate from the drop-down list.
Use EST for RadSec Client Provisioning
Enable the Use EST for RadSec Client Provisioning toggle switch to allow EST certificates to be used in RadSec applications.
Note:Assign EST profiles to the device for configuration. For more information, see EST Profile.
RadSec CA
Select an RadSec server CA from the drop-down list to validate the certificate presented by the TLS (RadSec) server.
RadSec Client Cert
Select an RadSec client certificate from the drop-down list to be used by the device to identify itself to the RadSec server.
ClearPass CA
Select a ClearPass CA from the drop-down list to verify to identity of the ClearPass server.
802.1X Supplicant CA
Select a 802.1X supplicant CA from the drop-down list to be used for 802.1X authentication.
802.1X Supplicant Client Cert
Select an 802.1X supplicant client certificate from the drop-down list to be used for 802.1X authentication.
WebCC CA
Select an WebCC CA from the drop-down list for web content classification.
IoT CA
Select an IoT CA from the drop-down list for IoT.
ClearPass CA
Select an ClearPass CA from the drop-down list for ClearPass authentication.
Gateway Parameters
Server Certificate
In the Server Certificate section, enter the following:
- Captive Portal Server Certificate—Select a captive portal server certificate from the drop-down list.
- Server Certificate—Select a server certificate from the drop-down list.
VPN Client Certificate
In the VPN Client Certificate section, enter the following:
- Server Certificate—Select a captive portal server certificate from the drop-down list.
- CA Certificate—Select a server certificate from the drop-down list.
VPN Client Certificate Group
Select a VPN client certificate group from the list.
To add a VPN client certificate group, enter the following:
-
Click + Add.
The Add VPN Client Certificate Group window is displayed.
-
In the Add VPN Client Certificate Group window, enter the following
- Server Certificate—Select a captive portal server certificate from the drop-down list.
- CA Certificate—Select a server certificate from the drop-down list.
- Click Add.
Revocation Checkpoint
Click the Enable OCSP Responder check box to enable OCSP responder.
Select an OCSP certificate from the OCSP Certificate drop-down list.
Revocation Checkpoint
Select a revocation checkpoint certificate from the list.
To add the record for which you want to configure the revocation checkpoint, enter the following:
-
Click + Add.
The Add Revocation Checkpoint window is displayed.
-
In the Revocation Checkpoint window, enter the following
- Trusted Certificate—Select the CA certificate from the drop-down list for which you want to configure the revocation check point.
- Revocation Method 1—Select OCSP from the drop-down list as the primary check method.
- CRL File Name—Select the CRL file name from the drop down list.
- Enable OCSP Responder—Click the Enable OCSP Responder check box to enable OCSP responder.
- OCSP URL—Specify the OCSP server URL.
- OCSP Signed Cert—Select the required OCSP signer certificate from the drop-down list.
- OCSP Responder Cert—Select the required OCSP responder certificate from the drop-down list.
- Server Unreachable—Select one of the following:
- Fail-Over—Fails over to the revocation method 2, if configured.
- Allow Cert—Allows the certificate.
- Revoke Cert—Revokes the certificate.
- Timeout Period—Enter the timeout period in the text box in milliseconds(ms).
- Click Add.
-
Click Create.
The newly created network policy is displayed in the Certificate Usage list view. -
To edit a Certificate Usage profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The Edit Profile view is displayed in the side panel.
-
Edit the required parameters.
-
Click Update.
To delete an Certificate Usage profile network policy, hover on the profile name, and click the delete
icon.
Assigning Scope to a Certificate Usage Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the Security card, click the second radio button, and then click Certificate Usage.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Certificate Usage card, click Manage.
The Certificate Usage list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the Ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Certificate Usage list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the Ellipsis
icon. -
Select Unassign.
-
Select the required scope and click Unassign.
-
-
To customize the Certificate Usage profile list, click the Table Menu
icon. For more information, see Customizing List.