HPE7-A08 · Question #108
A customer reports that their HPE Aruba Networking ClearPass Guest captive portal is not functioning. The page loads but they are unable to browse after pressing connect. They have uploaded a valid…
The correct answer is B. captiveportal-login.aruba-training.com needs to be entered in the Address field for the ClearPass. Option B is correct because ClearPass Guest requires the Address field to contain the exact hostname used to serve the captive portal, and that hostname must match a name covered by the installed certificate. Since captiveportal-login.aruba-training.com is the expected portal…
Question
A customer reports that their HPE Aruba Networking ClearPass Guest captive portal is not functioning. The page loads but they are unable to browse after pressing connect. They have uploaded a valid and publicly trusted *. aruba-training.com certificate. Refer to the exhibit. Which would explain this issue?
Exhibits
Options
- Aaruba-training.com needs to be entered in the Address field for the ClearPass Guest
- Bcaptiveportal-login.aruba-training.com needs to be entered in the Address field for the ClearPass
- CHTTPS certificate is not required in ClearPass Guest
- DHTTPS wildcard certificates are not supported
How the community answered
(29 responses)- A17% (5)
- B72% (21)
- C7% (2)
- D3% (1)
Explanation
Option B is correct because ClearPass Guest requires the Address field to contain the exact hostname used to serve the captive portal, and that hostname must match a name covered by the installed certificate. Since captiveportal-login.aruba-training.com is the expected portal hostname and falls within the scope of the *.aruba-training.com wildcard certificate, entering it resolves the mismatch causing post-connect browsing failure - the client can't complete the redirect because the configured address doesn't align with the cert.
Why A is wrong: A wildcard cert like *.aruba-training.com covers subdomains only - it does not cover the bare root domain aruba-training.com. Entering that would still produce a certificate mismatch.
Why C is wrong: HTTPS certificates are absolutely required in ClearPass Guest for secure captive portal delivery; this is not optional.
Why D is wrong: ClearPass Guest fully supports wildcard certificates - there's no such limitation. The issue here is misconfiguration, not a feature restriction.
Memory tip: Remember "wildcard = one level deep." *.aruba-training.com hits something.aruba-training.com but misses the root. When the Address field and certificate hostname don't align, the portal loads but browsing breaks - that symptom is your cue to check the configured hostname.
Topics
Community Discussion
No community discussion yet for this question.

