Administrator Guide

Table Of Contents
the AP is not be approved as a secure AP until a network administrator manually changes the status of the
AP to verify that it is not compromised. If an AP is in this state due to connectivity problems, then the AP
recovers and is taken out of this hold state as soon as connectivity is restored.
Verifying Certificates
If you are unable to configure the control plane security feature on W-600 Series, W-6000M3, or W-3000 Series
controllers, verify that its Trusted Platform Module (TPM) and factory-installed certificates are present and
valid by accessing the controller’s command-line interface and issuing the show tpm cert-info command. If
the controller has a valid certificate, the output of the command appears similar to the output in the example
below.
(host) #show tpm cert-info
=====================================
TPM manufacturing factory certificate
=====================================
subject= /CN=BA0003137::00:1a:1e:00:89:b8
issuer= /DC=com/DC=arubanetworks/DC=ca/CN=DEVICE-CA1
serial=2E1DF0D10000004C8EE7
notBefore=Aug 6 22:50:04 2013 GMT
notAfter=Sep 14 03:21:14 2032 GMT
=====================================
Generated Factory certificate
=====================================
subject= /CN=BA0003137::00:1a:1e:00:89:b8/L=SW
issuer= /CN=BA0003137::00:1a:1e:00:89:b8
serial=2E1DF0D10000004C8EE7
notBefore=Aug 6 22:50:04 2013 GMT
notAfter=Sep 14 03:21:14 2032 GMT
If the controller displays the following output, it may have a corrupted or missing TPM and factory certificates.
Contact Dell support.
(host) #show tpm cert-info
Cannot get TPM and Factory Certificate Info.
Disabling Control Plane Security
If you disable control plane security on a standalone or local controller, all APs connected to that controller
reboot then reconnect to the controller over a clear channel.
If your disable control plane security on a master controller, APs directly connected to the master controller
reboot then reconnect to the master controller over a clear channel. However, its local controllers continue to
communicate with their APs over a secure channel until you save your configuration on the master controller.
Once you save the configuration, the changes are pushed down to the local controllers. At that point, any APs
connected to the local controllers also reboot and reconnect over a secure channel.
Verifying Whitelist Synchronization
To verify that a network of master and local controllers are correctly sharing their campus AP whitelists, check
the sequence numbers on the master and local controller whitelists.
l The sequence number value on a master controller should be the same as the remote sequence number on
the local controller.
l The sequence number value on a local controller should be the same as the remote sequence number on
the master controller.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Control Plane Security | 144