Jump to content

Recommended Posts

Posted

Hi all,

 

Certificate about to expire Certificate (value='Dummy Server Certificate'), (value='RADIUS EAP') will expire on (value='2017-04-09 15:40:06').

 

Certificate about to expire Certificate (value='Dummy Authority'), (value='RADIUS EAP') will expire on (value='2017-04-09 14:48:53').

 

Had these 2 warnings on my MSM this morning, any ideas on how I can replace them with new certs - or extend them?

 

Thanks

Posted

Hi Cblunt,

 

Had the exact same on our MSM760 this morning also, it advises that these certificates are used but I cannot see how.

 

Sam

  • Thanks 1
Posted
I have just had this message come up excatly the same as you guys, not sure what the 2 certificates are used for though, anyone got any ideas?
  • Thanks 1
Posted
I have just had this message come up excatly the same as you guys, not sure what the 2 certificates are used for though, anyone got any ideas?
  • Thanks 1
Posted (edited)
We don't use Raidus, but I spoke to our support company about them and they can be ignored... I didn't ask how it would affect anyone that does use Radius though... Edited by RichCowell
  • Thanks 1
Posted (edited)
We don't use Raidus, but I spoke to our support company about them and they can be ignored... I didn't ask how it would affect anyone that does use Radius though... Edited by RichCowell
  • Thanks 1
Posted
just talked to my previous boss who installed the system and he said these are dummy placeholder certificates just to show you where the actual ones have to go. They should not effect anything on the wireless switch.
Posted

In the same boat here, but with a MSM756zl, according to the HP MSM7xx Controllers Configuration Guide Page 298;

 

Default CA certificates

The following certificates are installed by default:

• SOAP API Certificate Authority: Before allowing a SOAP client to connect, the controller checks the certificate supplied by a SOAP client to ensure that it is issued by a trusted certificate authority (CA).

• Dummy Authority: Used by the internal RADIUS server. You should replace this with your own CA certificate.

• Entrust.net Secure Server Certification Authority: This is the Authorize.Net CA certificate. It is used to support credit card payments via Authorize.Net.

• Management Console Dummy Authority: Used when the management tool communicates with HP PCM/PMM software.

NOTE: For security reasons, you should replace the default certificates with your own.

 

I'm thinking I should have replaced the dummy certificates when I configured the controller, going to look into how to do this, but if anyone else has already done it and could post instructions that would save some time!

 

Thanks

Posted

Hi All,

 

HP advised that a firmware updated would fix the issue, however it hasnt. After another conversation with HP they have said unless your controller is acting as the RADIUS server it doesnt matter and you can delete the certificates. We have done this and it hasnt affected any services.

 

Hope this helps

 

Sam

Posted (edited)

Hi, I found this forum by googling why my MSM765zl suddenly had this certificate message as everyone else here does. I updated firmware from 6.6.00 to 6.6.5.0-23187 but the cert messages came back again.

 

I use the Radius feature for my wireless clients to use mac based authentication in the VSC against Bradford Networks NAC which keeps track of users macs and puts them on the correct vlan or puts them in the Registration vlan where they get a you must register with your AD credentials web portal.

 

I'm worried that the certs running out will break this mechanism, but I'm not sure if the MSM is the Radius server in my particular setup or if the Bradford appliance is acting as the Radius server. (EDIT: in MSM Authenticaion > Radius Profiles > Primary Radius Server has the IP of my Bradford appliance as the primary Radius server so perhaps I shouldnt worry) I will open a ticket with Bradford, hopefully not their only MSM controller customer.

 

Will follow up if I hear anything,

Squelchtone

 

 

PS and probably it's own question, but does anyone here ever update their controller and then lose visibility of all APs and you have to remote in or go reboot each AP for them to rediscover the controller so they show up in the Detected list? (controller LAN IP and AP IP's are on same vlan, no firewalls or acls to block them from talking, users connect to AP and dump out to the network, they dont tunnel back to controller for their internet access.)

Edited by squelchtone
Posted
Hi, I found this forum by googling why my MSM765zl suddenly had this certificate message as everyone else here does. I updated firmware from 6.6.00 to 6.6.5.0-23187 but the cert messages came back again.

 

I use the Radius feature for my wireless clients to use mac based authentication in the VSC against Bradford Networks NAC which keeps track of users macs and puts them on the correct vlan or puts them in the Registration vlan where they get a you must register with your AD credentials web portal.

 

I'm worried that the certs running out will break this mechanism, but I'm not sure if the MSM is the Radius server in my particular setup or if the Bradford appliance is acting as the Radius server. (EDIT: in MSM Authenticaion > Radius Profiles > Primary Radius Server has the IP of my Bradford appliance as the primary Radius server so perhaps I shouldnt worry) I will open a ticket with Bradford, hopefully not their only MSM controller customer.

 

Will follow up if I hear anything,

Squelchtone

 

 

PS and probably it's own question, but does anyone here ever update their controller and then lose visibility of all APs and you have to remote in or go reboot each AP for them to rediscover the controller so they show up in the Detected list? (controller LAN IP and AP IP's are on same vlan, no firewalls or acls to block them from talking, users connect to AP and dump out to the network, they dont tunnel back to controller for their internet access.)

 

Ok, Bradford Networks does not believe that these default certs are used in the process of my controller sending mac addresses over to the Bradford appliance, but they do have concerns that my wireless users may encounter problems as they connect to the access point. I told the Bradford tech that we use WPA2 for authentication, not RADIUS so I think my next step is to open a case with HP and see where that leads. Worst case fumbling around and getting/generating new CA certs and importing them into the wireless controller, right? =)

Posted

These certs are specifically marked 'Radius EAP'. EAP is only negotiated between the wireless client and the Radius Server. If the controller is passing off Radius authentication requests to an internal Radius server, then the controller is acting as the authenticator, and is not part of the EAP negotiation, and therefore these certs would not be used. If the controller is acting as the Radius Server, then these certs would be used.

 

I spoke to support as well and they also indicated that the factory dummy certs could be deleted if you were using an internal radius server.

 

John

Posted
These certs are specifically marked 'Radius EAP'. EAP is only negotiated between the wireless client and the Radius Server. If the controller is passing off Radius authentication requests to an internal Radius server, then the controller is acting as the authenticator, and is not part of the EAP negotiation, and therefore these certs would not be used. If the controller is acting as the Radius Server, then these certs would be used.

 

I spoke to support as well and they also indicated that the factory dummy certs could be deleted if you were using an internal radius server.

 

John

 

Thanks John, this makes a lot of sense.

 

I just went to Home > Security > Certificate Usage > clicked RADIUS EAP > and changed the cert drop down box for Authentication To The Peer to be: Dummy RADIUS Server Certificate, and down below that I went to Peer Authentication drop down and changed it to Dummy RADIUS Authority and clicked Save.

 

Then I went one tab back to Certificates Store, saw that the expiring ones no longer had anything used them, and clicked the trashcan (bin for my UK friends :-) icon and now all my icons are green and no more annoying warning.

 

I just disconnected a wireless client from the network, made sure the controller no longer saw it as connected, turned wifi back on, connected to wifi and everything is working great, so for anyone reading this down the road, you can rest easy that this shouldn't affect your end users, unless of course you actually are using RADIUS 802.1x authentication from client to AP/controller.

 

Thank you everyone,

Squelchtone

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...