
4 | ClearPass Guest 3.9 | Deployment Guide
Configuring the ClearPass Guest Subscription ID........................................45
Installing Subscription Updates ....................................................................46
Setup Completion .........................................................................................47
Chapter 4 Onboard.................................................................................................. 49
About ClearPass Onboard...................................................................................49
Onboard Deployment Checklist....................................................................49
Onboard Feature List ....................................................................................51
Supported Platforms.....................................................................................51
Public Key Infrastructure for Onboard ..........................................................52
Certificate Hierarchy ...............................................................................52
Revoking Unique Device Credentials............................................................53
Revoking Credentials to Prevent Network Access.................................54
Re-Provisioning a Device .......................................................................54
Network Requirements for Onboard.............................................................55
Using the Same SSID for the Provisioning and
Provisioned Networks ......................................................................55
Using a Different SSID for the Provisioning and
Provisioned Networks ......................................................................55
Configuring the Online Certificate Status Protocol for the
Provisioned Network........................................................................55
Configuring a Certificate Revocation List (CRL) for the
Provisioned Network........................................................................56
Network Architecture for Onboard................................................................56
Network Architecture for Onboard when Using ClearPass Guest .........57
The ClearPass Onboard Process..................................................................58
Devices Supporting Over-the-Air Provisioning.......................................58
Devices Supporting Onboard Provisioning ............................................61
Accessing Onboard .............................................................................................64
Configuring the User Interface for Device Provisioning ......................................64
Customizing the Device Provisioning Web Login Page ................................65
Using the {nwa_mdps_config} Template Function .......................................66
Configuring ClearPass Servers for Device Provisioning......................................66
Configuring the Certificate Authority ..................................................................68
Setting Up the Certificate Authority ..............................................................69
Setting Up a Root Certificate Authority.........................................................70
Setting Up an Intermediate Certificate Authority ..........................................72
Obtaining a Certificate for the Certificate Authority ......................................74
Using Microsoft Active Directory Certificate Services ..................................74
Installing a Certificate Authority’s Certificate ................................................77
Renewing the Certificate Authority’s Certificate ...........................................78
Configuring Data Retention Policy for Certificates .......................................79
Uploading Certificates for the Certificate Authority.............................................79
Viewing the Certificate Authority’s Trust Chain ............................................79
Creating a Certificate...........................................................................................80
Specifying the Identity of the Certificate Subject..........................................81
Issuing the Certificate Request .....................................................................82
Managing Certificates..........................................................................................82
Searching for Certificates..............................................................................83
Working with Certificates ..............................................................................83
Working with Certificate Signing Requests...................................................85
Requesting a Certificate ......................................................................................87
Providing a Certificate Signing Request in Text Format ...............................87
Providing a Certificate Signing Request File.................................................88
Specifying Certificate Properties ..................................................................89
Comentarios a estos manuales