cancel
Showing results for 
Search instead for 
Did you mean: 

How to generate certificates for 802.1x authentication for the access points? Thanks.

How to generate certificates for 802.1x authentication for the access points? Thanks.

dal
New Contributor II

How do i generate certificate requests for use in 802.1x authentication for the access points, as seen under Configuration -> Network Policy -> Additional Settings -> Secure Port Settings?

I tried to set them up with PEAP, but the radius server recieves messages where the username is set to INVALID for some reason.

So either I have to figure out what causes that, or try to use certificates, which is the way I really want to go.

 

Thanks.

1 ACCEPTED SOLUTION

samantha_lynn
Esteemed Contributor III

I'm sorry, I think there is some confusion on how these certs work. You would download the CSR from the HiveManager, import that in to your CA, your CA signs it, and should give you three things: The CA cert file (this is the intermediate and root certs concatenated together), the server cert file (this is the one the CA signs), and the key file. All you would need to do from there is import these in the the HiveManager, the HiveManager doesn't sign these again.

View solution in original post

14 REPLIES 14

dal
New Contributor II

Nothing?

Are there any examples at all out there that is outlining how to do this?

I can't be the only one.

dal
New Contributor II

I created a CSR, imported it to our CA server, and created a web server certificate.

But how do I sign it in Hivemanager?

And also; under Secure Port Settings, it asks for a Private Key File.

How do I get that? Do I just link to the same web server certificate?

 

Thanks.

samantha_lynn
Esteemed Contributor III

Thank you for clarifying. To generate a CSR you will want to go to Configuration> Expand the left hand side menu> Advanced Configuration> Keys and Certificates> Server CSR> Fill in the form and click "Create". You can import that into your DC so your DC can sign it.

dal
New Contributor II

It is AP250's, connected to a Cisco 2960x.

We use Hivemanager Classic, a standalone version that we host ourselves.

The default certificates will not work, unless we import them into our radius server of course.

samantha_lynn
Esteemed Contributor III

What client types are we plugging in to the switch port? The default certs should work fine. Also, what HiveManager platform are you using (HiveManager (formerly NG)(cloud.aerohive.com), or HiveManager Classic (myhive.aerohive.com))?

GTM-P2G8KFN