Users Guide

Table Of Contents
378 | Control Plane Security Dell PowerConnect ArubaOS 5.0 | [User Guide
To view information about the campus AP whitelist via the command-line interface, use the commands
described in Table 72.
Modifying an AP in the Campus AP Whitelist
Use the following procedure to modify a campus AP entry’s certificate type, state, description and revoked status
via the WebUI.
1. Access the master controller WebUI, and navigate to Configuration>AP Installation.
State The Campus AP Whitelist reports one of the following states for each campus AP:
z unapproved-no-cert: AP has no certificate and is not approved.
z unapproved-factory-cert: AP has a preinstalled certificate that was not approved.
z approved-ready-for-cert: The AP has been approved as a valid campus AP and is
ready to receive a certificate.
z certified-factory-cert: The AP is already has a factory certificate. If an AP has the
factory-cert certificate type and is in the certified-factory-cert state, then that
campus AP will not be re-issued a new certificate if automatic certificate
provisioning is enabled.
z certified-controller-cert: AP has an approved certificate from the controller.
z certified-hold-factory-cert: An AP is put in this state when the controller thinks the
AP has been certified with a factory certificate yet the AP requests to be certified
again. Since this is not a normal condition, the AP will not be approved as a secure
AP until a network administrator manually changes the status of the AP to verify that
it is not compromised.
NOTE: If an AP is in this state due to connectivity problems, then the AP will recover
and will be out of this hold state as soon as connectivity is restored.
z certified-hold-controller-cert: An AP is put in this state when the controller thinks
the AP has been certified with a controller certificate yet the AP requests to be
certified again. Since this is not a normal condition, the AP will not be approved as a
secure AP until a network administrator manually changes the status of the AP to
verify that it is not compromised.
NOTE: If an AP is in this state due to connectivity problems, then the AP will recover
and will be out of this hold state as soon as connectivity is restored.
Description If defined, a brief description of the campus AP.
Revoked Shows if the AP’s secure status has been revoked.
Revoked Text An optional, brief statement describing why the AP was revoked.
Table 72 View the Campus AP Whitelist via the CLI
Command Description
show whitelist-db cpsec
[mac-address <macaddr>]
Shows detailed information for each AP in the whitelist, including the
AP’s MAC address, approved state, certificate type and description.
Include the optional mac-address <macaddr> parameters to view
data for a single entry.
show whitelist-db cpsec-status The command gives aggregate information for the numbers of APs in
each of the following categories:
z Total entries
z Approved entries
z Unapproved entries
z Certified entries
z Certified hold entries
z Revoked entries
z Marked for deletion entries
Table 71 View Campus AP Whitelist Parameters
Parameter Description