Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HPE6-A88 Exam - Topic 7 Question 4 Discussion

An organization is setting up a ClearPass server for their network authentication. The administrator has installed a certificate issued by an internal Certificate Authority. The clients cannot fully validate the server's certificate. What additional step must the administrator take to ensure the clients can successfully validate the certificate?
B) Install the root certificate from the internal Certificate Authority on all client devices.
A) Disable the trust check in the client's validation process.
C) Reissue the certificate from a public Certificate Authority.

HPE6-A88 Exam - Topic 7 Question 4 Discussion

Actual exam question for HP's HPE6-A88 exam
Question #: 4
Topic #: 7
[All HPE6-A88 Questions]

An organization is setting up a ClearPass server for their network authentication. The administrator has installed a certificate issued by an internal Certificate Authority. The clients cannot fully validate the server's certificate. What additional step must the administrator take to ensure the clients can successfully validate the certificate?

Show Suggested Answer Hide Answer
Suggested Answer: B

Certificate trust is hierarchical. For a client device to trust a server certificate, it must trust the Root CA that signed it. If an internal CA is used, its root certificate is not present in the default trust stores of consumer devices. Therefore, the administrator must deploy that root certificate to every client (typically via GPO, MDM, or Onboard) so they can successfully verify the identity of the ClearPass server during the EAP handshake.


Contribute your Thoughts:

0/2000 characters
Albert
3 days ago
Are we sure the internal CA is set up correctly? Sounds sketchy.
upvoted 0 times
...
Sabine
8 days ago
Disabling trust checks (A) is a bad idea, don’t do that!
upvoted 0 times
...
Mignon
14 days ago
Wait, why not just use a public CA? Seems easier!
upvoted 0 times
...
Phillip
19 days ago
Totally agree with B, otherwise they won't trust it.
upvoted 0 times
...
Billye
24 days ago
B is the right move! Root cert needs to be on all clients.
upvoted 0 times
...
Murray
29 days ago
I feel like installing the root certificate is the most straightforward solution here, but I hope I’m not missing something!
upvoted 0 times
...
Jospeh
3 months ago
Reissuing the certificate from a public CA could solve the issue, but that seems like overkill for an internal setup.
upvoted 0 times
...
Man
3 months ago
I'm not entirely sure, but disabling the trust check seems risky. I remember a similar question where we had to ensure trust was established.
upvoted 0 times
...
Devorah
3 months ago
I think the clients need to trust the internal CA, so maybe we have to install the root certificate on them?
upvoted 0 times
...

Save Cancel