nerdexam
HP

HPE6-A78 · Question #39

You have an Aruba solution with multiple Mobility Controllers (MCs) and campus APs. You want to deploy a WPA3-Enterprise WLAN and authenticate users to Aruba ClearPass Policy Manager (CPPM) with…

The correct answer is D. Deploy certificates to clients, signed by a CA that CPPM trusts. For WPA3-Enterprise with EAP-TLS, it's crucial that clients have a trusted certificate installed for the authentication process. EAP-TLS relies on a mutual exchange of certificates for authentication. Deploying client certificates signed by a CA that CPPM trusts ensures that…

Implementing and Configuring Aruba Network Security

Question

You have an Aruba solution with multiple Mobility Controllers (MCs) and campus APs. You want to deploy a WPA3-Enterprise WLAN and authenticate users to Aruba ClearPass Policy Manager (CPPM) with EAP-TLS. What is a guideline for ensuring a successful deployment?

Options

  • AAvoid enabling CNSA mode on the WLAN, which requires the internal MC RADIUS server.
  • BEnsure that clients trust the root CA for the MCs' Server Certificates.
  • CEducate users in selecting strong passwords with at least 8 characters.
  • DDeploy certificates to clients, signed by a CA that CPPM trusts.

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    13% (5)
  • D
    79% (30)

Explanation

For WPA3-Enterprise with EAP-TLS, it's crucial that clients have a trusted certificate installed for the authentication process. EAP-TLS relies on a mutual exchange of certificates for authentication. Deploying client certificates signed by a CA that CPPM trusts ensures that the ClearPass Policy Manager can verify the authenticity of the client certificates during the TLS handshake process. Trust in the root CA is typically required for the server side of the authentication process, not the client side, which is covered by the client's own certificate. 5216 - The EAP-TLS Authentication Protocol.

Topics

#WPA3-Enterprise#EAP-TLS#certificate deployment#ClearPass

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice