Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HPE6-A88 Exam - Topic 7 Question 4 Discussion

An organization is setting up a ClearPass server for their network authentication. The administrator has installed a certificate issued by an internal Certificate Authority. The clients cannot fully validate the server's certificate. What additional step must the administrator take to ensure the clients can successfully validate the certificate?
B) Install the root certificate from the internal Certificate Authority on all client devices.
A) Disable the trust check in the client's validation process.
C) Reissue the certificate from a public Certificate Authority.

HPE6-A88 Exam - Topic 7 Question 4 Discussion

Actual exam question for HP's HPE6-A88 exam
Question #: 4
Topic #: 7
[All HPE6-A88 Questions]

An organization is setting up a ClearPass server for their network authentication. The administrator has installed a certificate issued by an internal Certificate Authority. The clients cannot fully validate the server's certificate. What additional step must the administrator take to ensure the clients can successfully validate the certificate?

Show Suggested Answer Hide Answer
Suggested Answer: B

Certificate trust is hierarchical. For a client device to trust a server certificate, it must trust the Root CA that signed it. If an internal CA is used, its root certificate is not present in the default trust stores of consumer devices. Therefore, the administrator must deploy that root certificate to every client (typically via GPO, MDM, or Onboard) so they can successfully verify the identity of the ClearPass server during the EAP handshake.


Contribute your Thoughts:

0/2000 characters
Mendy
4 days ago
Option C seems risky. Public CA might not be necessary.
upvoted 0 times
...
Jutta
10 days ago
Agreed, without the root cert, they can't validate.
upvoted 0 times
...
Art
15 days ago
I think option B is the best choice. Clients need the root certificate.
upvoted 0 times
...
Frederica
20 days ago
Exactly! Installing the root cert is crucial for validation.
upvoted 0 times
...
Carin
25 days ago
B makes sense. It's a standard practice for internal CAs.
upvoted 0 times
...
Edelmira
1 month ago
C is unnecessary. Public CA isn't needed for internal use.
upvoted 0 times
...
Johnathon
1 month ago
A is risky. Disabling trust checks isn't a good idea.
upvoted 0 times
...
Mee
1 month ago
Agreed, without it, they can't trust the server.
upvoted 0 times
...
Veta
2 months ago
I think B is the right answer. Clients need the root certificate.
upvoted 0 times
...
Albert
2 months ago
Are we sure the internal CA is set up correctly? Sounds sketchy.
upvoted 0 times
...
Sabine
2 months ago
Disabling trust checks (A) is a bad idea, don’t do that!
upvoted 0 times
...
Mignon
2 months ago
Wait, why not just use a public CA? Seems easier!
upvoted 0 times
...
Phillip
2 months ago
Totally agree with B, otherwise they won't trust it.
upvoted 0 times
...
Billye
2 months ago
B is the right move! Root cert needs to be on all clients.
upvoted 0 times
...
Murray
3 months ago
I feel like installing the root certificate is the most straightforward solution here, but I hope I’m not missing something!
upvoted 0 times
...
Jospeh
4 months ago
Reissuing the certificate from a public CA could solve the issue, but that seems like overkill for an internal setup.
upvoted 0 times
...
Man
4 months ago
I'm not entirely sure, but disabling the trust check seems risky. I remember a similar question where we had to ensure trust was established.
upvoted 0 times
...
Devorah
4 months ago
I think the clients need to trust the internal CA, so maybe we have to install the root certificate on them?
upvoted 0 times
...

Save Cancel