Configuring EAP-TLS Profile
To create an EAP-TLS profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the Menu
icon. -
In the Central NAC card, click Manage.
The NAC Monitoring page is displayed.
-
Click the Configuration
icon. The configuration view appears, which displays the Authentication Profiles, Authorization Policies, Identity Management, Visitors, and Messaging cards.
-
In the Authentication Profiles card, click Manage.
The authentication profiles that are created are listed in this page.
-
Click Create Profile to create an authentication profile.
-
In the Create Profile side panel, configure the following parameters:
-
Name—Enter a name of the profile.
-
Description—Enter a description of the authentication profile.
-
Authentication Type—Select EAP-TLS.
-
Network—Select a network to be configured with the EAP-TLS profile from the Network drop-down list.
-
To choose a wired connection, select the Use for wired connection check box.
Note:This option can be enabled only for one profile for any authentication type.
-
-
Identity Store—Select an identity store from the drop-down list.
-
-
Under EAP-TLS Settings enter the following details:
-
Organization Name—Enter an organization name.
-
Certificate—Select between Default or Custom EAP-TLS server certificate.
-
For a Default certificate, select an option from the EAP-TLS Client Valid Days drop-down. This indicates the lifetime for the certificate.
Note:With foundation license, the option to select Default or Custom certificate is disabled. Also, the option to modify EAP-TLS Client Valid Days is disabled until you get an option to select a certificate type.
-
For a Custom certificate, see Bring Your Own Certificates (BYOC).
-
-
-
To add an UEM Onboarding, click the Add
icon. -
In the Add UEM Instance panel, configure the following parameters:
-
Name—Enter a name for the UEM instance.
-
Type—Select Microsoft Intune or Jamf Pro.
-
Extension—Select a specific extension from the drop-down list.
Click Create.
The UEM Instance is created and is listed under the UEM Onboarding.
-
Validating Intune Credentials
Based on the error codes, the following messages appear when validating Intune credentials during creating or updating of an authentication profile with UEM as Intune.
"invalid_tenant_identifier": "Invalid Tenant ID." "invalid_client_identifier": "Invalid Client ID." "invalid_client_secret": "Invalid Client Secret." "missing_scep_api_permission": "Missing required Intune API permission. Ensure that application registration has permissions for SCEP challenge validation." "missing_graph_api_permission": "Missing required Microsoft Graph API permission. Ensure that app registration has 'Application.Read.All' permissions."
Viewing Web Portal
Administrators can view and access the web portal from the Authentication Profiles page.
-
In the Authentication Profiles page, hover over an EAP-TLS profile and click the ellipsis
icon. A pop-up menu is displayed.
-
Click View Portal.
The captive portal page opens in a new browser window.
Editing an EAP-TLS Profile
-
In the Authentication Profiles page, click the EAP-TLS profile.
The Edit Profile panel is displayed.
-
Click the UEM instance under UEM Onboarding.
The Edit UEM Instance is displayed with the following links:
-
SCEP URL
-
SCEP Challenge Webhook URL
-
SCEP Challenge Webhook Authentication Header
-
Download Certificate
Note:Use the SCEP URL and certificate to configure both SCEP and trusted certificate profiles in Microsoft Intune.
-