Dell Powerconnect W-ClearPass Virtual Appliances W-ClearPass Guest 6.0 Deploym - Page 107

Configuring Basic Provisioning Settings, Configuring Certificate Properties for Device Provisioning

Page 107 highlights

Configuring Basic Provisioning Settings To configure basic provisioning settings: 1. Go to Onboard > Provisioning Settings and click the General tab. The first part of the Device Provisioning Settings form's General tab is used to specify basic information about Onboard provisioning. 2. The Name and Description fields are used internally to identify this set of Onboard settings for the network administrator. These values are never displayed to the user during device provisioning. 3. Use the Organization field to provide the name of your organization; this will be displayed to the user during the device provisioning process. Configuring Certificate Properties for Device Provisioning To specify the properties for certificates issued to devices: 1. Go to Onboard > Provisioning Settings, click the General tab, and scroll to the Certificate Authority row. 2. The Certificate Authority drop-down list can be used to select a different certificate authority. By default, there is only a single certificate authority. 3. Use the Validity Period text field to specify the maximum length of time for which a client certificate issued during device provisioning will remain valid. 4. The Clock Skew Allowance text field adds a small amount of time to the start and end of the client certificate's validity period. This permits a newly issued certificate to be recognized as valid in a network where not all devices are perfectly synchronized. For example, if the current time is 12:00, and the clock skew allowance is set to the default value of 15 minutes, then the client certificate will be issued with a "not valid before" time of 11:45. In this case, if the authentication server that receives the client certificate has a time of 11:58, it will still recognize the certificate as valid. If the clock skew allowance was set to 0 minutes, then the authentication server would not recognize the certificate as valid until its clock has reached 12:00. The default of 15 minutes is reasonable. If you expect that all devices on the network will be synchronized then the value may be reduced. A setting of 0 minutes is not recommended as this does not permit any variance in clocks between devices. When issuing a certificate, the certificate's validity period is determined as follows: Dell Networking W-ClearPass Guest 6.0 | Deployment Guide Configuring Basic Provisioning Settings | 107

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320

Configuring Basic Provisioning Settings
To configure basic provisioning settings:
1.
Go to
Onboard > Provisioning Settings
and click the
General
tab. The first part of the Device Provisioning
Settings form’s General tab is used to specify basic information about Onboard provisioning.
2.
The
Name
and
Description
fields are used internally to identify this set of Onboard settings for the network
administrator. These values are never displayed to the user during device provisioning.
3.
Use the
Organization
field to provide the name of your organization; this will be displayed to the user during the
device provisioning process.
Configuring Certificate Properties for Device Provisioning
To specify the properties for certificates issued to devices:
1.
Go to
Onboard > Provisioning Settings
, click the
General
tab, and scroll to the
Certificate Authority
row.
2.
The
Certificate Authority
drop-down list can be used to select a different certificate authority. By default, there
is only a single certificate authority.
3.
Use the
Validity Period
text field to specify the maximum length of time for which a client certificate issued
during device provisioning will remain valid.
4.
The
Clock Skew Allowance
text field adds a small amount of time to the start and end of the client certificate’s
validity period. This permits a newly issued certificate to be recognized as valid in a network where not all
devices are perfectly synchronized.
For example, if the current time is 12:00, and the clock skew allowance is set to the default value of 15 minutes,
then the client certificate will be issued with a “not valid before” time of 11:45. In this case, if the
authentication server that receives the client certificate has a time of 11:58, it will still recognize the certificate
as valid. If the clock skew allowance was set to 0 minutes, then the authentication server would not recognize the
certificate as valid until its clock has reached 12:00.
The default of 15 minutes is reasonable. If you expect that all devices on the network will be synchronized then
the value may be reduced. A setting of 0 minutes is not recommended as this does not permit any variance in
clocks between devices.
When issuing a certificate, the certificate’s validity period is determined as follows:
Dell Networking W-ClearPass Guest 6.0 | Deployment Guide
Configuring Basic Provisioning Settings |
107