cancel
Showing results for 
Search instead for 
Did you mean: 

NAC Alarm if RADIUS certificate is about to expire

NAC Alarm if RADIUS certificate is about to expire

Michael_Kirchne
Contributor
Hi,

I just had a major issue beacuse the RADIUS certificate of the NAC/IAM appliance did expire. This caused a big problem because of IEEE 802.1X Authentication was used. The problem was quickly resolved but it could have been avoided if an alarm would have been present.

Best scenario for future releases: If the RADIUS (or any NAC certificate) is about to expire (e.g. in 1 or 2 months) a warning is presented. And in the last days an alarm is caused.

I hope this idea will be realized to avoid major .1X problems 🙂

Best Regards
Michael
18 REPLIES 18

StephanH
Valued Contributor III
Hi Ron,

thank you for the fast answer,

Best regards,
Stephan

Regards Stephan

Ronald_Dvorak
Honored Contributor
Yes, make sure it's enabled and some kind of notification like email is set......

bbf0a72b35a84f2fbe5b1effa06f2323_RackMultipart20170802-55334-m6vcgo-EMC_NAC_cert_alarm_inline.png



-Ron

StephanH
Valued Contributor III
Hello folks,

do we have this function meanwhile?

Regards
Stephan
Regards Stephan

Michael_Kirchne
Contributor
Hey folks,

any news from Product Management yet? Would be cool to hear if there is any progress

@ Mark: The SCEP feature would be extremly helpful.

Also the certificate converting into PKCS8 format is not a big deal but very strange to customers who are not familiar with OpenSSL. An import of PKCS12 certificates would be much easier.

Best Regards
Michael

Mark_Lamond
New Contributor III
I would like to see this also.

I realise you can see the date in the "Manage Appliance Certificates" dialog, but there is nothing to show what format the date is in - is it US or UK format?

Something unambiguous showing "Days until RADIUS certificate expiry" or the date as "17 September 2014" would be useful. That way the expiry cannot be misinterpreted.

Or perhaps support for NAC to obtain / renew certificates automatically using SCEP?

Thanks,
Mark.

GTM-P2G8KFN