nerdexam
HP

HPE7-A02 · Question #16

A company issues user certificates to domain computers using its Windows CA and the default user certificate template. You have set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to…

The correct answer is A. Configure rules to strip the domain name from the username. To fix the issue where authorization fails because the usernames do not exist in the authentication source, you can configure rules in HPE Aruba Networking ClearPass Policy Manager (CPPM) to strip the domain name from the username. When certificates are issued by a Windows CA…

Troubleshooting and Monitoring Network Security

Question

A company issues user certificates to domain computers using its Windows CA and the default user certificate template. You have set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to authenticate 802.1X clients with those certificates. However, during tests, you receive an error that authorization has failed because the usernames do not exist in the authentication source. What is one way to fix this issue and enable clients to successfully authenticate with certificates?

Options

  • AConfigure rules to strip the domain name from the username.
  • BChange the authentication method list to include both PEAP MSCHAPv2 and EAP-TLS.
  • CAdd the ClearPass Onboard local repository to the authentication source list.
  • DRemove EAP-TLS from the authentication method list and add TEAP there instead.

How the community answered

(29 responses)
  • A
    55% (16)
  • B
    14% (4)
  • C
    24% (7)
  • D
    7% (2)

Explanation

To fix the issue where authorization fails because the usernames do not exist in the authentication source, you can configure rules in HPE Aruba Networking ClearPass Policy Manager (CPPM) to strip the domain name from the username. When certificates are issued by a Windows CA, the username in the certificate often includes the domain (e.g., [email protected]). ClearPass might not be able to find this format in the authentication source. By stripping the domain name, you ensure that ClearPass searches for just the username (e.g., user) in the authentication source, allowing successful authentication.

Topics

#EAP-TLS#certificate authentication#username mapping#ClearPass troubleshooting

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice