Monday, 13 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > The perfect certificate migration until it wasn’t: How certificates can break RADIUS trusts
Global Market

The perfect certificate migration until it wasn’t: How certificates can break RADIUS trusts

Last updated: January 16, 2026 12:29 pm
Published January 16, 2026
Share
surveillance cameras privacy security
SHARE

Most significantly, including the basis certificates on the AOS change is famous as an automatic task, which is a stark distinction as seen on AOS-CX.

In sharp distinction, the Aruba OS-CX change makes use of Downloadable Person Roles (DURs), which centralize the coverage definition and alter the enforcement supply technique totally. With DURs, all advanced position parameters, together with VLANs (e.g., VLAN 100, VLAN 120), lessons and insurance policies are configured centrally on ClearPass utilizing an in depth GUI. ClearPass generates the whole CLI script for the person position. To ship this coverage, the change doesn’t depend on a RADIUS VSA set off; as an alternative, the AOS-CX change should execute a REST API name over SSL to ClearPass to obtain the total position script when it’s required for an endpoint. Since DURs are downloaded as wanted, they’re unstable and saved solely in reminiscence, being eliminated upon reboot, which is a key distinction from the persistent LURs used on AOS switches.

To allow this safe API communication, the belief mannequin shifts from RADIUS shared secrets and techniques to certificate-based authentication, the change will need to have NTP and DNS configured, and the ClearPass root certificates have to be manually imported right into a trusted anchor profile (pki ta profile) on the AOS-CX switch. Moreover, a devoted downloadable person position account (e.g., duradmin) have to be created on the change and authenticated to ClearPass with the aruba person position obtain privilege stage, granting the change permission to execute the obtain.

This diagram summarizes the distinction:

Swaitlana Agnihotri

See also  AWS Migration Competency Status Attained by Cloudelligent

What really occurred

In our case, all endpoint gadgets had already been up to date with the brand new Sectigo root certificates, and ClearPass itself was absolutely migrated from Entrust to Sectigo, so every part appeared aligned on the floor. The problem emerged solely the place there was port bounce or reboot on these switches, main for Re-auth once more for shoppers linked. As soon as ClearPass started presenting the brand new Sectigo chain, the switches not trusted its HTTPS id as they nonetheless had Entrust certificates on them, inflicting authentication failures. ArubaOS switches have been usually capable of get better routinely by redownloading the right certificates after reboot or throughout RADIUS communication, although a couple of required the RADIUS configuration to be eliminated and re-added to set off a contemporary certificates fetch.

Nonetheless, ArubaOS-CX switches couldn’t get better on their very own as a result of they depend on a manually imported trusted anchor, with the Entrust root now invalid; DUR downloads failed instantly after any reboot or port bounce. Endpoints may authenticate on the RADIUS stage, however the change couldn’t obtain their required roles, leaving them unable to affix the community.

Source link

TAGGED: break, certificate, certificates, Migration, perfect, RADIUS, Trusts, wasnt
Share This Article
Twitter Email Copy Link Print
Previous Article Edge AI comes to fleet video as Netradyne enables real-time in-cab search Edge AI comes to fleet video as Netradyne enables real-time in-cab search
Next Article First Insight brings conversational AI in retail First Insight brings conversational AI in retail
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Good Springs Capital Raises $570M for Inaugural Investment Fund

Good Springs Capital LP, a NYC-based non-public funding agency centered on partnering with founders, households,…

January 18, 2025

Wearable sticker turns hand movements into communication

Researchers have developed a wearable PDMS sensor that makes use of a FBG to sense…

February 29, 2024

BlackRock, OpenAI and more expected to announce sizeable UK investments

BlackRock is predicted to announce £500 million of funding into UK knowledge centres, in accordance…

September 15, 2025

Macquarie breaks ground on AI & cloud facility in Sydney

Macquarie Information Centres has commenced the development of its new IC3 Tremendous West knowledge centre…

June 15, 2024

HistoSonics Raises $102M in Series D Financing

HistoSonics, a Minneapolis, MN-based producer of the Edison® Histotripsy System and novel histotripsy remedy platforms, closed…

August 19, 2024

You Might Also Like

Nvidia GTC 2026 Vera Rubin
Global Market

Nvidia Rubin GPUs may be delayed, slowing the next phase of AI infrastructure

By saad
Yael Nardi Names Minimus as Chief Business Officer to Head Growth Strategy
Global Market

Yael Nardi joins Minimus as Chief Business Officer to head growth strategy

By saad
Cloud Security Concept: Businessman uses tablet on Secure Global Networking, Data Encryption, Firewall Protection, Continuous Monitoring, to Develop Smart Solutions from Digital Technology.
Global Market

Upstream network visibility is enterprise security’s new front line

By saad
AI Agents
Global Market

Cisco to acquire Galileo for AI observability

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.