Configuring EAP-TLS Profile

To create an EAP-TLS profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the Menu icon.

  2. In the Central NAC card, click Manage.

    The NAC Monitoring page is displayed.

  3. Click the Configuration icon.

    The configuration view appears, which displays the Authentication Profiles, Authorization Policies, Identity Management, Visitors, and Messaging cards.

  4. In the Authentication Profiles card, click Manage.

    The authentication profiles that are created are listed in this page.

  5. Click Create Profile to create an authentication profile.

  6. In the Create Profile side panel, configure the following parameters:

    • Name—Enter a name of the profile.

    • Description—Enter a description of the authentication profile.

    • Authentication Type—Select EAP-TLS.

    • Network—Select a network to be configured with the EAP-TLS profile from the Network drop-down list.

      • To choose a wired connection, select the Use for wired connection check box.

        Note:

        This option can be enabled only for one profile for any authentication type.

    • Identity Store—Select an identity store from the drop-down list.

  7. Under EAP-TLS Settings enter the following details:

    • Organization Name—Enter an organization name.

    • Certificate—Select between Default or Custom EAP-TLS server certificate.

      • For a Default certificate, select an option from the EAP-TLS Client Valid Days drop-down. This indicates the lifetime for the certificate.

        Note:

        With foundation license, the option to select Default or Custom certificate is disabled. Also, the option to modify EAP-TLS Client Valid Days is disabled until you get an option to select a certificate type.

  8. To add an UEM Onboarding, click the Add icon.

  9. In the Add UEM Instance panel, configure the following parameters:

    • Name—Enter a name for the UEM instance.

    • Type—Select Microsoft Intune or Jamf Pro.

    • Extension—Select a specific extension from the drop-down list.

    Click Create.

    The UEM Instance is created and is listed under the UEM Onboarding.

Validating Intune Credentials

Based on the error codes, the following messages appear when validating Intune credentials during creating or updating of an authentication profile with UEM as Intune.

"invalid_tenant_identifier": "Invalid Tenant ID." "invalid_client_identifier": "Invalid Client ID." "invalid_client_secret": "Invalid Client Secret." "missing_scep_api_permission": "Missing required Intune API permission. Ensure that application registration has permissions for SCEP challenge validation." "missing_graph_api_permission": "Missing required Microsoft Graph API permission. Ensure that app registration has 'Application.Read.All' permissions."

Viewing Web Portal

Administrators can view and access the web portal from the Authentication Profiles page.

  1. In the Authentication Profiles page, hover over an EAP-TLS profile and click the ellipsis icon.

    A pop-up menu is displayed.

  2. Click View Portal.

    The captive portal page opens in a new browser window.

Editing an EAP-TLS Profile

  1. In the Authentication Profiles page, click the EAP-TLS profile.

    The Edit Profile panel is displayed.

  2. Click the UEM instance under UEM Onboarding.

    The Edit UEM Instance is displayed with the following links:

    • SCEP URL

    • SCEP Challenge Webhook URL

    • SCEP Challenge Webhook Authentication Header

    • Download Certificate

    Note:

    Use the SCEP URL and certificate to configure both SCEP and trusted certificate profiles in Microsoft Intune.