EST Profile

EST supports automatic enrollment of certificates with the EST Server. The certificates can now be enrolled or re-enrolled automatically by configuring an EST profile on the device. Certificate enrollment with EST allows you to use your own PKI instead of the factory or self-signed certificates available on the device. This enables you to have maximum visibility and control over the management of the PKI used and can address any issues related to security in a scaled environment.

Creating an EST Profile

To create an EST Profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to an EST Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Site Collections, Sites, Devices, and Device Groups level, complete the following steps before step 4:
      1. Select Site Collections, Sites, Devices, or Device Groups in the left navigation menu.
      2. Select a site collection, site, device, or device group from the list view depending on the level where you are creating the profile.
      3. Select the device type from the Device Function drop-down list.

  3. On the Security card, click the second radio button, and then click EST.

    If you create the profile in the Library, then click the second radio button on the Security card, and then click EST.
    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the EST card, click Manage.

    The EST list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed

  5. Configure the parameters as described in the following table.

    Table 1: EST Profile Parameters

    Parameter

    Description

    Create as a local profile

    Select this option if you want to configure this profile as local.

    The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the EST profile.

    Description

    Enter a brief description for the EST profile.

    EST Activate

    Select this check box to activate the EST profile.

    EST CA Certificate

    Select the EST CA Certificate from the drop-down list.

    IP Address/FQDN  

    Hostname of the EST server.

    Port

    Enter the port value of the EST server. The default value is 443.

    Arbitrary Label

    Set the arbitrary label for the EST URL to distinguish it from the other EST profiles running on the EST server.

    Arbitrary Label Enrolment

    Set an arbitrary enrollment label for EST URL.

    Arbitrary Label Re-Enrolment

    Set an arbitrary re-enrollment label for EST URL.

    Password Type

    Set the password type to either Challenge Password or User Password.

    Note:

    The Challenge Password is only applicable to APs and Gateways.

    Switch Parameters

    Retry Interval

    Enter the time interval between each request to be sent to the EST server.

    Retry Count

    Enter the maximum number of authentication requests that can be sent to the EST server.

    EST-Server Re-Enrolment-Prior-Expiry

    Enter the re-enrollment time interval prior to expiry of EST server.

     

    VRF

    Select a VRF from the drop-down list. To add a new VRF, complete the following steps:

    1. Click New VRF.
    2. In the Create VRF page, enter a name and description in the Name and Description text-box.

    Allow Certificate Download

    Select this check-box to allow downloading of the EST certificate.

    Allow HTTP Digest Authorisation

    Select this check-box to allow HTTP Digest Authorisation.

  6. Click Create.
    The newly created network policy is displayed in the EST list view.

  7. To edit a EST profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.

    2. The Edit Profile view is displayed in the side panel.

    3. Edit the required parameters.

    4. Click Update.

  8. To delete an EST profile network policy, hover on the profile name, and click the delete icon.

Assigning Scope to an EST Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.

    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the Security card, click the second radio button, and then click EST.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the EST card, click Manage.

    The EST list view is displayed.

  4. Hover on the profile to which you want to assign a scope and click the Ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Add icon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The EST list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the Ellipsis icon.

    2. Select Unassign.

    3. Select the required scope and click Unassign.

  12. To customize the EST profile list, click the Table Menu icon. For more information, see Customizing List.