Passpoint Identity Provider Profile
Passpoint is a Wi-Fi certified solution that enables the mobile devices to automatically authenticate on enterprise Wi-Fi networks using their cellular credentials. is a Wi-Fi certified solution that enables the mobile devices to automatically authenticate on enterprise Wi-Fi networks using their cellular credentials. Once a user accesses the Wi-Fi network offered at a location, the Passpoint-enabled client devices will automatically connect on subsequent visits. This eliminates the need for users to search for and choose a network, request Wi-Fi access, and re-enter authentication credentials on subsequent visits. Passpoint automates the authentication process, enabling more seamless connectivity between the Wi-Fi networks and mobile devices, all while delivering enterprise-level security. Passpoint provisioning supports onboarding of new devices (with or without a SIM card) by establishing credential information and providing policy information to the mobile device.
Creating a Passpoint Identity Provider Profile
To create an Passpoint Identity Provider, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a Passpoint Identity Provider Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Groups level, complete the following steps before step 4:
- Select Site Collections, Sites, Devices, or Device Groups in the left navigation menu.
- Select a site collection, site, device, or device group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Security card, click the second radio button, and then click Passpoint Identity Provider
If you create the profile in the Library, then click the second radio button on the Security card, and then click Passpoint Identity Provider.
Alternatively, you can complete the following steps:-
On the Security card, click Manage.
-
On the Passpoint Identity Provider card, click Manage.
The Passpoint Identity Provider list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed
-
Configure the parameters as described in the following table.
Table 1: Passpoint Identity Provider Profile Parameters
Parameter
Description
Create as a local profile
Select this option if you want to configure this profile as local.
The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.
Name
Enter the name of the Passpoint Identity Provider profile.
Description
Enter a brief description for the Passpoint Identity Provider profile.
Encoding
Select the realm encoding from the drop-down list.
-
UTF8
-
RFC4282
NAI Realm Names
Realm Name
Enter a name for the realm in the text box. Click
to add another realm name. Click
to add another real name.EAP Methods Credentials
EAP Method
Select an EAP method from the drop-down list. Click
to add another EAP method.Authentication ID
Select an authentication ID from the drop-down list. Click
to add another authentication ID.Authentication Value
Select an authentication value from the drop-down list. Click
to add another authentication value. -
-
Click Create.
The newly created network policy is displayed in the Passpoint Identity Provider list view. -
To edit a Passpoint Identity Provider profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The Edit Profile view is displayed in the side panel.
-
Edit the required parameters.
-
Click Update.
To delete an Passpoint Identity Provider profile network policy, hover on the profile name, and click the delete
icon.
Assigning Scope to a Passpoint Identity Provider Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the Security card, click the second radio button, and then click Passpoint Identity Provider.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Passpoint Identity Provider card, click Manage.
The Passpoint Identity Provider list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the Ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Passpoint Identity Provider list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the Ellipsis
icon. -
Select Unassign.
-
Select the required scope and click Unassign.
-
-
To customize the Passpoint Identity Provider profile list, click the Table Menu
icon. For more information, see Customizing List.