Bring Your Own Certificates (BYOC)
BYOC is an advanced feature and is available only with the subscription license.
HPE Aruba Networking Central NAC provisions users with the bring your own certificates (BYOC) service. With this service, users can select their own certificates for setting up secured connections.
To configure using a custom certificate, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the Menu
icon. -
In the Central NAC card, click Manage.
The NAC Monitoring page is displayed.
-
Click the Configuration
icon. The configuration view appears, which displays the Authentication Profiles, Authorization Policies, Identity Management, Visitors, and Messaging cards.
-
In the Authentication Profiles card, click Manage.
-
Click .
-
In the Create Profile side panel, configure the following parameters:
-
Name—Enter a name of the profile.
-
Description—Enter a description of the authentication profile.
-
Authentication Type—Select EAP.
-
Network—Select the SSID network that you want to configure with the profile from the drop-down list.
-
Identity Store—Select the required identity store from the drop-down list.
-
Under EAP-TLS Settings, enter the following details:
-
Organization Name—Enter the organization name.
-
Certificate—Choose Custom certificate.
-
EAP-TLS Server Certificate—Enter the EAP-TLS server certificate details.
-
EAP-TLS Server Key—Enter the EAP-TLS server key or a private key. This key can either be encrypted or unencrypted.
-
EAP-TLS Server Key Passphrase—Enter a passphrase if the EAP-TLS server key is an encrypted key.
-
EAP-TLS Client CA Chain—Enter the trust chain.
-
-
OCSP Check—Select Enable OCSP Check if you want to validate the certificate revocation status.
-
Override OCSP URL—If the OCSP URL is present in the certificate, then enter an override OCSP URL.
-
OCSP Check Failure Response—If you are unable to reach the OCSP server, then select one of the options:
-
Reject all authentications
-
Allow authentications if the certificate date is valid
-
-
-
-
If the EAP-TLS server certificate is close to expiring (within 3 months) a warning banner is displayed as follows:
If the EAP-TLS server certificate has already expired, an error banner is displayed as follows:
-
Click Create.
The authentication profile is created with the custom certificate and is listed in the Authentication Profiles page.
Note:The HPE Aruba Networking Onboard URL cannot be used for client configuration.