{"id":21651934,"url":"https://github.com/poweraruba/powerarubacp","last_synced_at":"2025-07-06T19:37:34.591Z","repository":{"id":34618979,"uuid":"141305826","full_name":"PowerAruba/PowerArubaCP","owner":"PowerAruba","description":"PowerShell module to manage Aruba ClearPass (CPPM)","archived":false,"fork":false,"pushed_at":"2024-01-29T20:00:02.000Z","size":850,"stargazers_count":18,"open_issues_count":1,"forks_count":7,"subscribers_count":6,"default_branch":"master","last_synced_at":"2025-04-11T20:45:25.848Z","etag":null,"topics":["api-rest","aruba","aruba-clearpass","clearpass","clearpass-api","cmdlets","cppm","hpe","networking","powershell","powershell-module"],"latest_commit_sha":null,"homepage":"","language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/PowerAruba.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-07-17T15:03:38.000Z","updated_at":"2025-02-27T10:42:24.000Z","dependencies_parsed_at":"2024-11-25T07:50:22.361Z","dependency_job_id":"66c67fbc-4d9e-4b31-a013-a59fc19e6393","html_url":"https://github.com/PowerAruba/PowerArubaCP","commit_stats":null,"previous_names":[],"tags_count":9,"template":false,"template_full_name":null,"purl":"pkg:github/PowerAruba/PowerArubaCP","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PowerAruba%2FPowerArubaCP","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PowerAruba%2FPowerArubaCP/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PowerAruba%2FPowerArubaCP/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PowerAruba%2FPowerArubaCP/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/PowerAruba","download_url":"https://codeload.github.com/PowerAruba/PowerArubaCP/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/PowerAruba%2FPowerArubaCP/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":263961035,"owners_count":23536164,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["api-rest","aruba","aruba-clearpass","clearpass","clearpass-api","cmdlets","cppm","hpe","networking","powershell","powershell-module"],"created_at":"2024-11-25T07:50:19.384Z","updated_at":"2025-07-06T19:37:34.557Z","avatar_url":"https://github.com/PowerAruba.png","language":"PowerShell","funding_links":[],"categories":[],"sub_categories":[],"readme":"\n# PowerArubaCP\n\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://www.powershellgallery.com/packages/PowerArubaCP/\" alt=\"PowerShell Gallery Version\"\u003e\n        \u003cimg src=\"https://img.shields.io/powershellgallery/v/PowerArubaCP.svg\" /\u003e\u003c/a\u003e\n    \u003ca href=\"https://www.powershellgallery.com/packages/PowerArubaCP/\" alt=\"PS Gallery Downloads\"\u003e\n        \u003cimg src=\"https://img.shields.io/powershellgallery/dt/PowerArubaCP.svg\" /\u003e\u003c/a\u003e\n    \u003c!--\n    \u003ca href=\"https://www.powershellgallery.com/packages/PowerArubaCP/\" alt=\"PS Platform\"\u003e\n        \u003cimg src=\"https://img.shields.io/powershellgallery/p/PowerArubaCP.svg\" /\u003e\u003c/a\u003e\n    --\u003e\n\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://github.com/PowerAruba/PowerArubaCP/graphs/commit-activity\" alt=\"GitHub Last Commit\"\u003e\n        \u003cimg src=\"https://img.shields.io/github/last-commit/PowerAruba/PowerArubaCP/master.svg\" /\u003e\u003c/a\u003e\n    \u003ca href=\"https://raw.githubusercontent.com/PowerAruba/PowerArubaCP/master/LICENSE\" alt=\"GitHub License\"\u003e\n        \u003cimg src=\"https://img.shields.io/github/license/PowerAruba/PowerArubaCP.svg\" /\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/PowerAruba/PowerArubaCP/graphs/contributors\" alt=\"GitHub Contributors\"\u003e\n        \u003cimg src=\"https://img.shields.io/github/contributors/PowerAruba/PowerArubaCP.svg\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://twitter.com/PowerAruba\" alt=\"Twitter\"\u003e\n            \u003cimg src=\"https://img.shields.io/twitter/follow/PowerAruba.svg?style=social\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\nThis is a Powershell module for configure an Aruba ClearPass (CPPM).\n\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"https://raw.githubusercontent.com/PowerAruba/PowerArubaCP/master/Medias/PowerArubaCP.png\" width=\"250\" height=\"250\" /\u003e\n\u003c/p\u003e\n\nWith this module (version 0.7.0) you can manage:\n\n- [API Client](#api-client) (Add / Get / Remove)\n- [Application License](#application-license) (Add / Get / Remove)\n- [Authentication Method and Source](#Authentication-Method-and-Source) (Get Auth Source and Method)\n- [Certificate](#Certificate) (Get Cluster, Service, Server and Trust List Certificate)\n- [CPPM](#clearpass-version) (Get Version)\n- [Device Fingerprint](#device-fingerprint) (Add /Get)\n- [Endpoint](#endpoint) (Add / Get / Set / Remove and Add / Set / Remove [Attribute](#attribute))\n- [Enforcement](#Enforcement) (Get Enforcement Policy / Profile)\n- [Local User](#local-user) (Add / Get / Set / Remove and Add / Set / Remove [Attribute](#attribute))\n- [Network Device](#Network-device) (Add / Get / Set / Remove a Network Device and Add / Set / Remove [Attribute](#attribute))\n- [Network Device Group](#network-device-group) (Add / Get / Set / Remove a Network Device Group and Add/remove Member)\n- [Role](#role)\n- [Server](#server) (Get Configuration, Version)\n- [Service](#service) (Get / Enable / Disable)\n- [Static Host List](#static-host-list) (Add / Get / Set / Remove a Static Host List and Add/Remove Member)\n- [VM](#vm) (Deploy and Configure ClearPass VM (for initial setup))\n\nThere is some extra feature\n- [Invoke API](#Invoke-API)\n- [Multi Connection](#MultiConnection)\n- [Filtering](#Filtering)\n\nMore functionality will be added later.\n\nTested with Aruba ClearPass (using release 6.8.x, 6.9.x, 6.10.x, 6.11.x and 6.12.x)  \nApplication Licence, Service and Static Host List are not supported on Clearpass \u003c 6.8.0  \nDevice Fingerprint are not supported on Clearpass \u003c 6.9.0  \n\n# Usage\n\nAll resource management functions are available with the Powershell verbs GET, ADD, SET, REMOVE.  \nFor example, you can manage NAS (NetworkDevice) with the following commands:\n- `Get-ArubaCPNetworkDevice`\n- `Add-ArubaCPNetworkDevice`\n- `Set-ArubaCPNetworkDevice`\n- `Remove-ArubaCPNetworkDevice`\n\n# Requirements\n\n- Powershell 5 or 6.x/7.x (Core) (If possible get the latest version)\n- A ClearPass (with release \u003e= 6.8.x) and API Client enable\n\n# Instructions\n### Install the module\n```powershell\n# Automated installation (Powershell 5 and later):\n    Install-Module PowerArubaCP\n\n# Import the module\n    Import-Module PowerArubaCP\n\n# Get commands in the module\n    Get-Command -Module PowerArubaCP\n\n# Get help\n    Get-Help Add-ArubaCPNetworkDevice -Full\n```\n\n# Examples\n\n### Connecting to the ClearPass using API\n\nThe first thing to do is to get API Client\nthere is two methods to connect, using [client_id/client_secret](#Use-API-client_idclient_secret) or [token](#Use-API-Token) \n\n#### Use API client_id/client_secret\n\n\nGo on WebGUI of your ClearPass, on Guest Modules\n![](./Medias/CPPM_Guest_API.PNG)  \nGo on `Administration` =\u003e `API Services` =\u003e `API Clients`\n\n![](./Medias/CPPM_Create_API_Client.PNG)  \nCreate a `New API Client`\n- Client ID : a client name (for example PowerArubaCP)\n- Operator Profile : Super Administrator\n- Grant type : Client credentials\n- Access Token Lifetime : You can increment ! (24 hours !)\n\nClick on `Create API Client`\n\n```powershell\n# Connect to the Aruba Clearpass using client_id/client_secret\n    Connect-ArubaCP 192.0.2.1 -client_id PowerArubaCP -client_secret QRFttyxOmWX3NopMIYzKysj30wvIMxAwB6kUy7uJc67B\n\n    Name                           Value\n    ----                           -----\n    token                          7aa3de0be5ea230ea92b6de0bafa14d7a76e2305\n    invokeParams                   {DisableKeepAlive, SkipCertificateCheck}\n    server                         192.0.2.1\n    port                           443\n    version                        6.8.4\n\n```\n\n#### Use API Token\n\nLike for client_id/client_secret, generate a API Client but you don't need to store the Client Secret\n\nOn `API Clients List`, select the your client\n![](./Medias/CPPM_Generate_Access_Token.PNG)  \n\nClick on `Generate Access Token`\n\n![](./Medias/CPPM_Get_Token.PNG)  \nAnd kept the token (for example : 70680f1d19f86110800d5d5cb4414fbde7be12ae)\n\n\nAfter connect to an Aruba ClearPass with the command `Connect-ArubaCP` :\n\n```powershell\n# Connect to the Aruba Clearpass using Token\n    Connect-ArubaCP 192.0.2.1 -token 70680f1d19f86110800d5d5cb4414fbde7be12ae\n\n    Name                           Value\n    ----                           -----\n    token                          70680f1d19f86110800d5d5cb4414fbde7be12ae\n    invokeParams                   {DisableKeepAlive, SkipCertificateCheck}\n    server                         192.0.2.1\n    port                           443\n    version                        6.8.4\n```\n\n### Invoke API\nfor example to get ClearPass version\n\n```powershell\n# get ClearPass version using API\n    Invoke-ArubaCPRestMethod -method \"get\" -uri \"api/cppm-version\"\n\n    app_major_version   : 6\n    app_minor_version   : 7\n    app_service_release : 2\n    app_build_number    : 105008\n    hardware_version    : CLABV\n    fips_enabled        : False\n    eval_license        : False\n    cloud_mode          : False\n```\n\nif you get a warning about `Unable to connect` Look [Issue](#Issue)\n\nto get API uri, go to ClearPass Swagger (https://CPPM-IP/api-docs)\n![](./Medias/CPPM_API_Docs.PNG)  \n\nAnd chooce a service (for example Platform)\n![](./Medias/CPPM_API_Docs_platform.PNG)  \n\n### API Client\n\nYou can create a new API Client `Add-ArubaCPApiClient`, retrieve its informations `Get-ArubaCPApiClient` or delete it `Remove-ArubaCPApiClient`.\n\n```powershell\n# Create an API Client\n    Add-ArubaCPApiClient -client_id MyAPIClient -grant_types client_credentials -profile_id 1\n\n    client_id                    : MyAPIClient\n    client_secret                : $2y$10$OXRszKzBSH7hP5QwgZ3cCuNZwbGaddb767l0Kx52Ww.RPEhBfbj6u\n    client_description           :\n    grant_types                  : client_credentials\n    redirect_uri                 :\n    operating_scope              :\n    profile_id                   : 1\n    auto_confirm                 : False\n    enabled                      : True\n    scope                        :\n    user_id                      :\n    access_lifetime              : 8 hours\n    refresh_lifetime             : 14 days\n    operating_scope_label        : ClearPass REST API\n    profile_name                 : Super Administrator\n    client_public                : False\n    client_refresh               : False\n    access_token_lifetime        : 8\n    access_token_lifetime_units  : hours\n    refresh_token_lifetime       : 14\n    refresh_token_lifetime_units : days\n    id                           : MyAPIClient\n    _links                       : @{self=}\n\n\n# Get information about API Client\n    Get-ArubaCPApiClient -client_id MyAPIClient | Format-Table\n\n    client_id   client_secret      client_description grant_types        redirect_uri operating_scope profile_id auto_confirm enabled scope\n    ---------   -------------      ------------------ -----------        ------------ --------------- ---------- ------------ ------- -----\n    MyAPIClient $2y$10$OXRszKzB...                    client_credentials                              1                 False    True\n\n# Remove an API Client\n    $ac = Get-ArubaCPApiClient -client_id MyAPIClient\n    $ac | Remove-ArubaCPApiClient\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove API Client\" on target \"MyAPIClient\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"):\n```\n\n### Application License\n\nYou can create add Application License `Add-ArubaCPApplicationLicense`, retrieve its information `Get-ArubaCPApplicationLicense` or delete it `Remove-ArubaCPApplicationLicense`.\n\n```powershell\n# Add Application License (Onboard)\n    Add-ArubaCPApplicationLicense -product_name Onboard -license_key \"-----BEGIN CLEARPASS ONBOARD LICENSE KEY----- .... \"\n\n    id                : 3002\n    product_id        : 8\n    product_name      : Onboard\n    license_key       : -----BEGIN CLEARPASS ONBOARD LICENSE KEY-----\n                        .......\n                        -----END CLEARPASS ONBOARD LICENSE KEY-----\n    license_type      : Evaluation\n    user_count        : 100\n    duration          : 90\n    duration_units    : days\n    license_added_on  : 18/04/2021 13:45:27\n    activation_status : False\n    _links            : @{self=}\n\n\n# Get information about Application License\n    Get-ArubaCPApplicationLicense -product_name Onboard | Format-Table\n\n    id product_id product_name license_key\n    -- ---------- ------------ -----------\n    3002          8 Onboard      -----BEGIN CLEARPASS ONBOARD LICENSE KEY-----...\n\n# Remove Application License Onboard\n    $al = Get-ArubaCPApplicationLicense -product_name Onboard\n    $al | Remove-ArubaCPApplicationLicense\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Application License\" on target \"3002 (Onboard)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"):\n```\n\n### Authentication Method and Source\n\nYou can retrieve its Authentication information of Method (EAP, PAP...) `Get-ArubaCPAuthMethod` or Source (LDAP, HTTP...) `Get-ArubaCPAuthSource`\n\n```powershell\n# Get Auth Method information\n    Get-ArubaCPAuthMethod\n\n    id            : 1\n    name          : [PAP]\n    description   : Default settings for PAP\n    method_type   : PAP\n    details       : @{encryption_scheme=auto}\n    inner_methods : {}\n    _links        : @{self=}\n\n    id            : 2\n    name          : [MSCHAP]\n    description   : Default settings for MSCHAP\n    method_type   : MSCHAP\n    details       :\n    inner_methods : {}\n    _links        : @{self=}\n\n    id            : 3\n    name          : [EAP TLS]\n    description   : Default settings for EAP-TLS\n    method_type   : EAP-TLS\n    details       : @{override_cert_url=false; ocsp_enable=none; session_cache_enable=true; autz_required=true; certificate_comparison=none; \n                    session_timeout=6}\n    inner_methods : {}\n    _links        : @{self=}\n    ...\n\n# Get Auth Source information\n    Get-ArubaCPAuthSource | Format-List\n\n    id name                         description                                                                        type  use_for_authorization\n    -- ----                         -----------                                                                        ----  ---------------------\n    1 [Local User Repository]      Authenticate users against Policy Manager local user database                      Local                  True\n    2 [Guest User Repository]      Authenticate guest users against Policy Manager local database                     Local                  True\n    3 [Guest Device Repository]    Authenticate guest devices against Policy Manager local database                   Local                  True\n    4 [Endpoints Repository]       Authenticate endpoints against Policy Manager local database                       Local                  True\n    5 [Onboard Devices Repository] Authenticate Onboard devices against Policy Manager local database                 Local                  True\n    6 [Admin User Repository]      Authenticate users against Policy Manager admin user database                      Local                  True\n    7 [Denylist User Repository]   Denylist database with users who have exceeded bandwidth or session related limits Local                  True\n    9 [Time Source]                Authorization source for implementing various time functions                       Local                  True\n   10 [Social Login Repository]    Authenticate users against Policy Manager social login database                    Local                  True\n  100 [Zone Cache Repository]      Access attributes cached by Context Server Actions in previous sessions            HTTP                   True\n    8 [Insight Repository]         Insight database with session information for users and devices                    Local                  True\n```\n\n### Certificate\n\nYou can retrieve its Cluster Certificate information of Method (HTTPS, RadSec, Database...) `Get-ArubaCPClusterCertificate`,\nServer (HTTPS, RadSec, Database...) `Get-ArubaCPServerCertificate` or Service `Get-ArubaCPServiceCertificate` or Certificate Trust List `Get-ArubaCPServiceCertificate`\n\n```powershell\n# Get Cluster Certificate\n    Get-ArubaCPClusterCertificate\n\n    service_id           : 1\n    service_name         : RADIUS\n    certificate_type     : RADIUS Server Certificate\n    subject              : CN=secure.arubademo.net\n    expiry_date          : Mar 15, 2024 20:21:15 PDT\n    issue_date           : Feb 12, 2023 19:21:15 PST\n    issued_by            : CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US\n    validity             : Valid\n    root_ca_cert         :\n    intermediate_ca_cert : {@{subject=CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US; \n                        expiry_date=May 03, 2031 00:00:00 PDT; issue_date=May 03, 2011 00:00:00 PDT; issued_by=CN=Go Daddy Root Certificate Authority - G2, O=\"GoDaddy.com, Inc.\", \n                        L=Scottsdale, ST=Arizona, C=US; validity=Valid; public_key_algorithm=RSA}, @{subject=CN=Go Daddy Root Certificate Authority - G2, O=\"GoDaddy.com, Inc.\", L=Scottsdale, \n                        ST=Arizona, C=US; expiry_date=May 30, 2031 00:00:00 PDT; issue_date=Dec 31, 2013 23:00:00 PST; issued_by=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy \n                        Group, Inc.\", C=US; validity=Valid; public_key_algorithm=RSA}}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    enabled              : True\n    public_key_algorithm : RSA\n\n    service_id           : 2\n    service_name         : HTTPS(ECC)\n    certificate_type     : HTTPS(ECC) Server Certificate\n    subject              : CN=clearpass-sjc1.arubademo.net\n    expiry_date          : Jun 07, 2025 15:36:29 PDT\n    issue_date           : Jun 08, 2023 15:36:29 PDT\n    issued_by            : CN=clearpass-sjc1.arubademo.net\n    validity             : Valid\n    root_ca_cert         :\n    intermediate_ca_cert : {}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    enabled              : False\n    public_key_algorithm : EC\n\n    service_id           : 7\n    service_name         : HTTPS(RSA)\n    certificate_type     : HTTPS(RSA) Server Certificate\n    subject              : CN=*.arubademo.net\n    expiry_date          : Jul 20, 2024 13:32:07 PDT\n    issue_date           : Jul 24, 2023 12:43:51 PDT\n    issued_by            : CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US\n    validity             : Valid\n    root_ca_cert         : @{subject=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy Group, Inc.\", C=US; expiry_date=Jun 29, 2034 10:06:20 PDT; issue_date=Jun 29, 2004 10:06:20 \n                        PDT; issued_by=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy Group, Inc.\", C=US; validity=Valid; public_key_algorithm=RSA}\n    intermediate_ca_cert : {@{subject=CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US; \n                        expiry_date=May 03, 2031 00:00:00 PDT; issue_date=May 03, 2011 00:00:00 PDT; issued_by=CN=Go Daddy Root Certificate Authority - G2, O=\"GoDaddy.com, Inc.\", \n                        L=Scottsdale, ST=Arizona, C=US; validity=Valid; public_key_algorithm=RSA}, @{subject=CN=Go Daddy Root Certificate Authority - G2, O=\"GoDaddy.com, Inc.\", L=Scottsdale, \n                        ST=Arizona, C=US; expiry_date=May 30, 2031 00:00:00 PDT; issue_date=Dec 31, 2013 23:00:00 PST; issued_by=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy \n                        Group, Inc.\", C=US; validity=Valid; public_key_algorithm=RSA}}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    enabled              : True\n    public_key_algorithm : RSA\n\n    service_id           : 21\n    service_name         : RadSec\n    certificate_type     : RadSec Server Certificate\n    subject              : CN=clearpass-sjc1.arubademo.net\n    expiry_date          : May 11, 2025 14:33:46 PDT\n    issue_date           : Nov 20, 2019 13:33:46 PST\n    issued_by            : CN=clearpass-sjc1.arubademo.net\n    validity             : Valid\n    root_ca_cert         :\n    intermediate_ca_cert : {}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    enabled              : True\n    public_key_algorithm : RSA\n\n    service_id           : 106\n    certificate_type     : Database Server Certificate\n    subject              : O=PolicyManager, CN=clearpass-sjc1.arubademo.net\n    expiry_date          : Mar 18, 2027 16:36:57 PDT\n    issue_date           : Mar 18, 2022 16:36:57 PDT\n    issued_by            : O=PolicyManager, CN=clearpass-sjc1.arubademo.net\n    validity             : Valid\n    root_ca_cert         : \n    intermediate_ca_cert : {}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    enabled              : True\n    public_key_algorithm : RSA\n\n# Get Server Certificate RadSec from Server clearpass-sjc1.arubademo.net\n    $server_uuid = (Get-ArubaCPServerConfiguration -name clearpass-sjc1.arubademo.net).server_uuid\n    Get-ArubaCPServerCertificate -server_uuid $server_uuid -service_name \"RadSec\"\n\n    service_id           : 21\n    service_name         : RadSec\n    certificate_type     : RadSec Server Certificate\n    subject              : CN=clearpass-sjc1.arubademo.net\n    expiry_date          : May 11, 2025 14:33:46 PDT\n    issue_date           : Nov 20, 2019 13:33:46 PST\n    issued_by            : CN=clearpass-sjc1.arubademo.net\n    validity             : Valid\n    root_ca_cert         :\n    intermediate_ca_cert : {}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    enabled              : True\n    public_key_algorithm : RSA\n    _links               : @{self=}\n\n# Get Service Certificate\n    Get-ArubaCPServiceCertificate\n\n    id                   : 3147\n    subject              : CN=*.arubademo.net\n    expiry_date          : Jul 20, 2024 13:32:07 PDT\n    issue_date           : Jul 24, 2023 12:43:51 PDT\n    issued_by            : CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US\n    validity             : Valid\n    root_ca_cert         : @{subject=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy Group, Inc.\", C=US; expiry_date=Jun 29, 2034 10:06:20 PDT; issue_date=Jun 29, 2004 10:06:20 \n                        PDT; issued_by=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy Group, Inc.\", C=US; validity=Valid}\n    intermediate_ca_cert : {@{subject=CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US; \n                        expiry_date=May 03, 2031 00:00:00 PDT; issue_date=May 03, 2011 00:00:00 PDT; issued_by=CN=Go Daddy Root Certificate Authority - G2, O=\"GoDaddy.com, Inc.\", \n                        L=Scottsdale, ST=Arizona, C=US; validity=Valid}, @{subject=CN=Go Daddy Root Certificate Authority - G2, O=\"GoDaddy.com, Inc.\", L=Scottsdale, ST=Arizona, C=US; \n                        expiry_date=May 30, 2031 00:00:00 PDT; issue_date=Dec 31, 2013 23:00:00 PST; issued_by=OU=Go Daddy Class 2 Certification Authority, O=\"The Go Daddy Group, Inc.\", \n                        C=US; validity=Valid}}\n    cert_file            : -----BEGIN CERTIFICATE-----\n                        [...]\n                        -----END CERTIFICATE-----\n    _links               : @{self=}\n\n    ...\n\n# Get Certificate Trust List (with details)\n\n    Get-ArubaCPCertTrustList -details\n\n    id                  : 2029\n    subject_DN          : CN=COMODO RSA Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB\n    issue_date          : 2010/01/18 16:00:00\n    expiry_date         : 2038/01/18 15:59:59\n    enabled             : True\n    valid               : valid\n    signature_algorithm : SHA384WITHRSA\n    public_key_format   : X.509\n    serial_number       : 101909084537582093308941363524873193117\n    cert_usage          : {Others}\n    issuer_DN           : C=GB,ST=Greater Manchester,L=Salford,O=COMODO CA Limited,CN=COMODO RSA Certification Authority\n    _links              : @{self=}\n\n    id                  : 2012\n    subject_DN          : OU=Class 3 Public Primary Certification Authority,O=VeriSign\\, Inc.,C=US\n    issue_date          : 1996/01/28 16:00:00\n    expiry_date         : 2028/08/02 16:59:59\n    enabled             : False\n    valid               : valid\n    signature_algorithm : SHA1WITHRSA\n    public_key_format   : X.509\n    serial_number       : 80507572722862485515306429940691309246\n    cert_usage          : {Others}\n    issuer_DN           : C=US,O=VeriSign\\, Inc.,OU=Class 3 Public Primary Certification Authority\n    _links              : @{self=}\n\n    [...]\n\n```\n\n\n### ClearPass Version\n\nYou can retrieve its informations `Get-ArubaCPCPPMVersion`.\n\n```powershell\n# Get ClearPass Version information \n    Get-ArubaCPCPPMVersion\n\n    app_major_version   : 6\n    app_minor_version   : 9\n    app_service_release : 5\n    app_build_number    : 131053\n    hardware_version    : CLABV\n    fips_enabled        : False\n    cc_enabled          : False\n    eval_license        : True\n    cloud_mode          : False\n```\n\n### Device Fingerprint\n\nYou can add Device Fingerprint `Add-DeviceFingerprint`, retrieve its informations `Get-DeviceFingerprint`.\n\n```powershell\n# Add Device Fingerprint (Device category, Family and name)\n    Add-ArubaCPDeviceFingerprint -mac_address 000102030405 -device_category Server -device_family ClearPass -device_name ClearPass VM\n\n    SUCCESS                                            _links\n    -------                                            ------\n    Successfully posted device fingerprint to profiler @{self=}\n\n# Add Device Fingerprint (IP Address)\n    Add-ArubaCPDeviceFingerprint -mac_address 000102030405 -ip 192.2.0.1\n\n    SUCCESS                                            _links\n    -------                                            ------\n    Successfully posted device fingerprint to profiler @{self=}\n\n# Add Device Fingerprint (hostname)\n    Add-ArubaCPDeviceFingerprint -mac_address 000102030405 -hostname CPPM\n\n    SUCCESS                                            _links\n    -------                                            ------\n    Successfully posted device fingerprint to profiler @{self=}\n\n# Get information about Device Fingerprint\n    Get-ArubaCPEndpoint -mac 000102030405 | Get-ArubaCPDeviceFingerprint\n\n    ip              : 192.0.2.1\n    hostname        : CPPM\n    updated_at      : 1622904104\n    device_category : Server\n    device_name     : ClearPass\n    device_family   : ClearPass\n    mac             : 000102030405\n    added_at        : 1622903816\n    _links          : @{self=}\n\n```\n\n### Endpoint\n\nYou can add Endpoint `Add-ArubaCPEndpoint`, retrieve its informations `Get-ArubaCPEndpoint`, modify its properties `Set-ArubaCPEndpoint` or delete it `Remove-ArubaCPEndpoint`.\n\n```powershell\n# Add Endpoint (Known)\n    Add-ArubaCPEndpoint -mac_address 00:01:02:03:04:05 -status Known\n\n    id          : 3179\n    mac_address : 000102030405\n    status      : Known\n    attributes  :\n    _links      : @{self=}\n\n# Get information about Endpoint\n    Get-ArubaCPEndpoint | Format-table\n\n    id mac_address  status  attributes _links\n    -- -----------  ------  ---------- ------\n    3004 00505690da3e Unknown            @{self=}\n    3173 00155d27ec00 Unknown            @{self=}\n    3003 0050569041da Unknown            @{self=}\n    3002 005056afddbb Unknown            @{self=}\n    3005 005056af007b Unknown            @{self=}\n    3030 00505680fb94 Unknown            @{self=}\n\n# Modified information (status and description) about Endpoint\n    Get-ArubaCPEndpoint -mac_address 00:01:02:03:04:05 | Set-ArubaCPEndpoint -status \"Unknown\" -description \"Change by PowerArubaCP\"\n\n    id          : 3179\n    mac_address : 000102030405\n    description : Change by PowerArubaCP\n    status      : Unknown\n    attributes  :\n    _links      : @{self=}\n\n# Remove Endpoint\n    $ep = Get-ArubaCPEndpoint -mac_address 00:01:02:03:04:05\n    $ep | Remove-ArubaCPEndpoint\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Endpoint\" on target \"3174 (000102030405)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"):Y\n```\n\n### Enforcement\n\nYou can retrieve its Enforcement Policy information (name, Type, Rules...) `Get-ArubaCPEnforcementPolicy`, or Enforcement Profile `Get-ArubaCPEnforcementProfile`\nNeed ClearPass \u003e= 6.11.0\n\n```powershell\n# Get Enforcement Policy\n    Get-ArubaCPEnforcementPolicy\n\n    id                          : 5\n    name                        : [Admin Network Login Policy]\n    description                 : Enforcement policy controlling access to Policy Manager Admin\n    enforcement_type            : TACACS\n    default_enforcement_profile : [TACACS+ Deny Profile]\n    rule_eval_algo              : evaluate-all\n    rules                       : {@{enforcement_profile_names=System.Object[]; condition=System.Object[]}, @{enforcement_profile_names=System.Object[]; condition=System.Object[]}, \n                                @{enforcement_profile_names=System.Object[]; condition=System.Object[]}, @{enforcement_profile_names=System.Object[]; condition=System.Object[]}…}\n    _links                      : @{self=}\n\n    id                          : 7\n    name                        : [AirGroup Enforcement Policy]\n    description                 : Enforcement policy controlling access for AirGroup devices\n    enforcement_type            : RADIUS\n    default_enforcement_profile : [AirGroup Response]\n    rule_eval_algo              : evaluate-all\n    rules                       : {@{enforcement_profile_names=System.Object[]; condition=System.Object[]}, @{enforcement_profile_names=System.Object[]; condition=System.Object[]}, \n                                @{enforcement_profile_names=System.Object[]; condition=System.Object[]}, @{enforcement_profile_names=System.Object[]; condition=System.Object[]}}\n    _links                      : @{self=}\n    [...]\n\n# Get Enforcement Profile\n    Get-ArubaCPEnforcementProfile\n\n    id          : 1\n    name        : [Allow Access Profile]\n    description : System-defined profile to allow network access\n    type        : RADIUS\n    action      : Accept\n    _links      : @{self=}\n\n    id          : 2\n    name        : [Deny Access Profile]\n    description : System-defined profile to deny network access\n    type        : RADIUS\n    action      : Reject\n    _links      : @{self=}\n\n    id          : 3\n    name        : [Drop Access Profile]\n    description : System-defined profile to drop the request\n    type        : RADIUS\n    action      : Drop\n    _links      : @{self=}\n    [...]\n```\n\n### Local User\n\nYou can add Endpoint `Add-ArubaCPLocalUser`, retrieve its informations `Get-ArubaCPLocalUser`, modify its properties `Set-ArubaCPLocalUser` or delete it `Remove-ArubaCPLocalUser`.\n\n```powershell\n# Add Local User\n    $mysecurepassword = ConvertTo-SecureString MyPassword -AsPlainText -Force\n    Add-ArubaCPLocaluser -user_id MyPowerArubaCP_userid -password $mysecurepassword -role_name \"[Employee]\"\n\n    id                    : 3085\n    user_id               : MyPowerArubaCP_userid\n    username              : MyPowerArubaCP_userid\n    role_name             : [Employee]\n    enabled               : True\n    change_pwd_next_login : False\n    attributes            :\n    _links                : @{self=}\n\n# Get information about Local User\n    Get-ArubaCPLocaluser | Format-Table\n\n    id user_id               username              role_name  enabled change_pwd_next_login attributes _links\n    -- -------               --------              ---------  ------- --------------------- ---------- ------\n    3085 MyPowerArubaCP_userid MyPowerArubaCP_userid [Employee]    True                 False            @{self=}\n\n# Modified information (username and and role) about Local User\n    Get-ArubaCPLocaluser -user_id MyPowerArubaCP_userid | Set-ArubaCPLocaluser -username MyPowerArubaCP_username -role [Guest]\n\n    id                    : 3085\n    user_id               : MyPowerArubaCP_userid\n    username              : MyPowerArubaCP_username\n    role_name             : [Guest]\n    enabled               : True\n    change_pwd_next_login : False\n    attributes            :\n    _links                : @{self=}\n\n# Remove Local User\n    $lu = Get-ArubaCPLocaluser -user_id MyPowerArubaCP_userid\n    $lu | Remove-ArubaCPLocaluser\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Local User\" on target \"3085 (MyPowerArubaCP_userid)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"): Y\n```\n\n### Network Device\n\nYou can create a new Network Device (NAS) `Add-ArubaCPNetworkDevice`, retrieve its informations `Get-ArubaCPNetworkDevice`, modify its properties `Set-ArubaCPNetworkDevice`, or delete it `Remove-ArubaCPNetworkDevice`.\n\n```powershell\n# Create a Network Device (NAS)\n    Add-ArubaCPNetworkDevice -name SW1 -ip_address 192.0.2.1 -radius_secret MySecurePassword -vendor Aruba -description \"Add by PowerArubaCP\"\n\n    id            : 3004\n    name          : SW1\n    description   : Add by PowerArubaCP\n    ip_address    : 192.0.2.1\n    radius_secret :\n    tacacs_secret :\n    vendor_name   : Aruba\n    coa_capable   : False\n    coa_port      : 3799\n    attributes    :\n    _links        : @{self=}\n\n\n# Get information about Network Device (NAS)\n    Get-ArubaCPNetworkDevice -name SW1 | Format-Table\n\n    id   name description         ip_address radius_secret tacacs_secret vendor_name coa_capable coa_port attributes\n    --   ---- -----------         ---------- ------------- ------------- ----------- ----------- -------- ----------\n    3004 SW1  Add by PowerArubaCP 192.0.2.1                              Aruba       False       3799\n\n# (Re)Configure Network Device (NAS)\n    Get-ArubaCPNetworkDevice -name SW1 | Set-ArubaCPNetworkDevice -ip_address 192.0.2.2 -vendor_name Hewlett-Packard-Enterprise\n\n    id            : 3004\n    name          : SW1\n    description   :\n    ip_address    : 192.0.2.2\n    radius_secret :\n    tacacs_secret :\n    vendor_name   : Hewlett-Packard-Enterprise\n    coa_capable   : True\n    coa_port      : 3799\n    attributes    :\n    _links        : @{self=}\n\n# Remove a Network Device (NAS)\n    $nad = Get-ArubaCPNetworkDevice -name SW1\n    $nad | Remove-ArubaCPNetworkDevice\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Network device\" on target \"3344 (SW1)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"):\n```\n\n### Network Device Group\n\nYou can create a new Network Device Group `Add-ArubaCPNetworkDeviceGroup`, retrieve its informations `Get-ArubaCPNetworkDeviceGroup`, modify its properties `Set-ArubaCPNetworkDeviceGroup`, or delete it `Remove-ArubaCPNetworkDeviceGroup` you can also add `Add-ArubaCPNetworkDeviceGroupMember` and remove `Remove-ArubaCPNetworkDeviceGroupMeMber` Member.\n\n```powershell\n# Create a Network Device Group (list IP)\n    Add-ArubaCPNetworkDeviceGroup -name NDG-list_ip -list_ip 192.0.2.1, 192.0.2.2\n\n    id           : 3037\n    name         : NDG-list_ip\n    group_format : list\n    value        : 192.0.2.1, 192.0.2.2\n    _links       : @{self=}\n\n# Create a Network Device Group (subnet)\n    Add-ArubaCPNetworkDeviceGroup -name NDG-subnet -subnet 192.0.2.0/24 -description \"Add via PowerArubaCP\"\n\n    id           : 3043\n    name         : NDG-subnet\n    description  : Add via PowerArubaCP\n    group_format : subnet\n    value        : 192.0.2.0/24\n    _links       : @{self=}\n\n# Get information about Network Device Group\n    Get-ArubaCPNetworkDeviceGroup | Format-Table\n\n    id name        group_format value                _links\n    -- ----        ------------ -----                ------\n    3037 NDG-list_ip list         192.0.2.1, 192.0.2.2 @{self=}\n    3043 NDG-subnet  subnet       192.0.2.0/24         @{self=}\n\n\n# (Re)Configure Network Device Group\n    Get-ArubaCPNetworkDeviceGroup -name NDG-subnet | Set-ArubaCPNetworkDeviceGroup -description \"Modified via PowerArubaCP\"\n\n    id           : 3043\n    name         : NDG-subnet\n    description  : Modified via PowerArubaCP\n    group_format : subnet\n    value        : 192.0.2.0/24\n    _links       : @{self=}\n\n#Add Member on the Network Device Group\n    Get-ArubaCPNetworkDeviceGroup -name NDG-list_ip | Add-ArubaCPNetworkDeviceGroupMember -list_ip 192.0.2.3\n\n    id           : 3037\n    name         : NDG-list_ip\n    group_format : list\n    value        : 192.0.2.1, 192.0.2.2, 192.0.2.3\n    _links       : @{self=}\n\n#Remove Member on the Network Device Group\n    Get-ArubaCPNetworkDeviceGroup -name NDG-list_ip | Remove-ArubaCPNetworkDeviceGroupMember -list_ip 192.0.2.1\n\n    id           : 3037\n    name         : NDG-list_ip\n    group_format : list\n    value        : 192.0.2.2, 192.0.2.3\n    _links       : @{self=}\n\n# Remove a Network Device Group\n    Get-ArubaCPNetworkDeviceGroup -name NDG-subnet | Remove-ArubaCPNetworkDeviceGroup\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Network Device Group\" on target \"3043 (NDG-subnet)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"): Y\n```\n\n### Role\n\nYou can add Role `Add-ArubaCPRole`, retrieve its informations `Get-ArubaCPRole`, modify its properties `Set-ArubaCPRole` or delete it `Remove-ArubaCPRole`.\n\n```powershell\n# Add Role\n    Add-ArubaCPRole -name PowerArubaCP_role\n\n    id   name              _links\n    --   ----              ------\n    3028 PowerArubaCP_role @{self=}\n\n# Get information about Role\n    Get-ArubaCPRole | Format-Table\n\n    id name                            description\n    -- ----                            -----------\n     3 [Guest]                         Default role for a Guest\n    12 [TACACS+ Read-only Admin]       Read-only administrator role for Policy Manager Admin\n    13 [TACACS+ API Admin]             API administrator role for Policy Manager Admin\n    14 [TACACS+ Help Desk]             Help desk role for Policy Manager Admin\n    15 [TACACS+ Receptionist]          Receptionist role for Policy Manager Admin\n    16 [TACACS+ Network Admin]         Network administrator role for Policy Manager Admin\n    18 [TACACS+ Super Admin]           Super administrator role for Policy Manager Admin\n    20 [Contractor]                    Default role for a contractor\n    21 [Other]                         Default role for another user or device\n    22 [Employee]                      Default role for an employee\n    [...]\n\n# Modified information (description) about a role\n    Get-ArubaCPRole -name PowerArubaCP_role | Set-ArubaCPRole -description \"Change by PowerArubaCP\"\n\n    id   name              description            _links\n    --   ----              -----------            ------\n    3028 PowerArubaCP_role Change by PowerArubaCP @{self=}\n\n# Remove Role\n    $r = Get-ArubaCPRole -name PowerArubaCP_role\n    $r | Remove-ArubaCProle\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Role\" on target \"3028 (PowerArubaCP_role)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"): Y\n```\n\n### Server\n\nYou can get Server Configuration `Get-ArubaCPServerConfiguration`, or version `Get-ArubaCPServerVersion`.\n\n\n```powershell\n# Get Server Configuration\n    Get-ArubaCPServerConfiguration\n\n    name                       : CPPM\n    local_server               : True\n    server_uuid                : 443c73db-aab3-49e4-a701-c21ef6945776\n    server_dns_name            : CPPM\n    fqdn                       :\n    server_ip                  :\n    management_ip              : 10.200.11.159\n    ipv6_server_ip             :\n    ipv6_management_ip         :\n    is_publisher               : True\n    extras                     :\n    is_insight_enabled         : True\n    is_insight_primary         : True\n    is_perfmon_enabled         : t\n    replication_status         : ENABLED\n    last_replication_timestamp :\n    is_profiler_enabled        : True\n    _links                     : @{self=}\n\n# Get Server Version\n    Get-ArubaCPServerVersion\n\n    cppm_version  guest_version installed_patches\n    ------------  ------------- -----------------\n    6.10.0.180076 6.10.0.180076 {}\n```\n\n### Service\n\nYou can retrieve information about Service `Get-ArubaCPService`, enable it `Enable-ArubaCPService`, or disable it `Disable-ArubaCPService`.\n\n```powershell\n\n#Get List of Service\n    Get-ArubaCPService | Format-Table\n\n    id name                                         type        template                         enabled order_no _links\n    -- ----                                         ----        --------                         ------- -------- ------\n    10 [Aruba Device Access Service]                TACACS      TACACS+ Enforcement                 True        3 @{self=}\n    1  [Policy Manager Admin Network Login Service] TACACS      TACACS+ Enforcement                 True        1 @{self=}\n    2  [AirGroup Authorization Service]             RADIUS      RADIUS Enforcement ( Generic )      True        2 @{self=}\n    11 [Guest Operator Logins]                      Application Aruba Application Authentication    True        4 @{self=}\n    13 [Device Registration Disconnect]             WEBAUTH     Web-based Authentication            True        6 @{self=}\n    12 [Insight Operator Logins]                    Application Aruba Application Authentication    True        5 @{self=}\n\n#Enable service on Guest Operator Logins\n    Get-ArubaCPService -Name \"[Guest Operator Logins]\" | Enable-ArubaCPService\n\n    id       : 11\n    name     : [Guest Operator Logins]\n    type     : Application\n    template : Aruba Application Authentication\n    enabled  : True\n    order_no : 4\n    _links   : @{self=}\n\n#Disable service on Guest Operator Logins (id)\n    Get-ArubaCPService -id 11 | Disable-ArubaCPService\n\n    id       : 11\n    name     : [Guest Operator Logins]\n    type     : Application\n    template : Aruba Application Authentication\n    enabled  : False\n    order_no : 4\n    _links   : @{self=}\n\n```\n\n### Static Host List\n\nYou can add Static Host List `Add-ArubaCPStaticHostList`, retrieve its informations `Get-ArubaCPStaticHostList`, modify its properties `Set-ArubaCPStaticHostList` or delete it `Remove-ArubaCPStaticHostList`, you can also add `Add-ArubaCPStaticHostListMember` and Remove `Remove-ArubaCPStaticHostListMember` Member (MAC or IPAddress).\n\n```powershell\n\n#Add Static Host List (with IPAddress)\n    Add-ArubaCPStaticHostList -name SHL-list-IPAddress -host_format list -host_type IPAddress -host_entries_address 192.0.2.1 -host_entries_description \"Add via PowerArubaCP\"\n\n    id           : 3040\n    name         : SHL-list-IPAddress\n    host_format  : list\n    host_type    : IPAddress\n    host_entries : {@{host_address=192.0.2.1; host_address_desc=Add via PowerArubaCP}}\n    _links       : @{self=}\n\n#Add Static Host List (with MACAddress)\n    Add-ArubaCPStaticHostList -name SHL-list-MACAddress -host_format list -host_type MACAddress -host_entries_address 00:01:02:03:04:05 -host_entries_description \"Add via PowerArubaCP\"\n\n    id           : 3041\n    name         : SHL-list-MACAddress\n    host_format  : list\n    host_type    : MACAddress\n    host_entries : {@{host_address=00-01-02-03-04-05; host_address_desc=Add via PowerArubaCP}}\n    _links       : @{self=}\n\n#Get list of Static Host List\n    Get-ArubaCPStaticHostList | Format-Table\n\n    id name                host_format host_type  host_entries                                                                _links\n    -- ----                ----------- ---------  ------------                                                                ------\n    3040 SHL-list-IPAddress  list        IPAddress  {@{host_address=192.0.2.1; host_address_desc=Add via PowerArubaCP}}         @{self=}\n    3041 SHL-list-MACAddress list        MACAddress {@{host_address=00-01-02-03-04-05; host_address_desc=Add via PowerArubaCP}} @{self=}\n\n#(Re)Configure a Static Host List\n    Get-ArubaCPStaticHostList -name SHL-list-IPAddress | Set-ArubaCPStaticHostList -description \"My SHL IP Address\"\n\n    id           : 3040\n    name         : SHL-list-IPAddress\n    description  : My SHL IP Address\n    host_format  : list\n    host_type    : IPAddress\n    host_entries : {@{host_address=192.0.2.1; host_address_desc=Add via PowerArubaCP}}\n    _links       : @{self=}\n\n\n#Add Member on the Static Host List\n    Get-ArubaCPStaticHostList -name SHL-list-MACAddress | Add-ArubaCPStaticHostListMember -host_entries_address 00:01:02:03:04:06 -host_entries_description \"Add via PowerArubaCP\"\n\n    id           : 3041\n    name         : SHL-list-MACAddress\n    host_format  : list\n    host_type    : MACAddress\n    host_entries : {@{host_address=00-01-02-03-04-05; host_address_desc=Add via PowerArubaCP}, @{host_address=00-01-02-03-04-06; \n                host_address_desc=Add via PowerArubaCP}}\n    _links       : @{self=}\n\n\n#Remove Member on the Static Host List\n    Get-ArubaCPStaticHostList -name SHL-list-MACAddress | Remove-ArubaCPStaticHostListMember -host_entries_address 00:01:02:03:04:06\n\n    id           : 3041\n    name         : SHL-list-MACAddress\n    host_format  : list\n    host_type    : MACAddress\n    host_entries : {@{host_address=00-01-02-03-04-05; host_address_desc=Add via PowerArubaCP}, @{host_address=00-01-02-03-04-06; \n                host_address_desc=Add via PowerArubaCP}}\n    _links       : @{self=}\n\n#Remove Static Host List\n    Get-ArubaCPStaticHostList -name SHL-list-MACAddress | Remove-ArubaCPStaticHostList\n\n    Confirm\n    Are you sure you want to perform this action?\n    Performing the operation \"Remove Static Host List\" on target \"3041 (SHL-list-MACAddress)\".\n    [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"Y\"): Y\n\n```\n\n### Attribute\n\nYou can add Attribute `Add-ArubaCPAttributesMember`, modify its `Set-ArubaCPAttributesMember` or remove it `Remove-ArubaCPAttributesMember` for Endpoint, Local User and Network Device\n\n```powershell\n\n#Add Attribute name \"Location and Syslocation\" with value PowerArubaCP to network Device NAD-PowerArubaCP\n    Get-ArubaCPNetworkDevice -name NAD-PowerArubaCP | Add-ArubaCPAttributesMember -name \"Location\", \"syslocation\" -value \"PowerArubaCP\", \"PowerArubaCP\"\n\n    id            : 3125\n    name          : NAD-PowerArubaCP\n    description   : Add by PowerArubaCP\n    ip_address    : 192.0.2.1\n    radius_secret :\n    tacacs_secret :\n    vendor_name   : Aruba\n    coa_capable   : False\n    coa_port      : 3799\n    attributes    : @{syslocation=PowerArubaCP; Location=PowerArubaCP}\n    _links        : @{self=}\n\n#Set Attribute name \"Disabled By\" with value PowerArubaCP to Local User MyPowerArubaCP_userid\n    Get-ArubaCPLocalUser -user_id MyPowerArubaCP_userid | Set-ArubaCPAttributesMember -attributes @{\"Disabled by\"=\"PowerArubaCP\"}\n\n    id                    : 3059\n    user_id               : MyPowerArubaCP_userid\n    username              : MyPowerArubaCP_userid\n    role_name             : [Guest]\n    enabled               : True\n    change_pwd_next_login : False\n    attributes            : @{Disabled by=PowerArubaCP}\n    _links                : @{self=}\n\n#Remove Attribute name \"Disabled By\" with value PowerArubaCP to Endpoint 00:01:02:03:04:05\n    Get-ArubaCPEndpoint -mac_address 00:01:02:03:04:05 | Remove-ArubaCPAttributesMember -name \"Disabled by\"\n\n    id          : 3001\n    mac_address : 000102030405\n    description :\n    status      : Unknown\n    attributes  : @{Compromised=true}\n    _links      : @{self=}\n\n```\n\n### VM\n\nYou can use PowerArubaCP for help to deploy ClearPass on VMware ESXi (With a vCenter)\nYou need to have [VMware.PowerCLI](https://developer.vmware.com/powercli) and [Set-VMKeystrokes](https://www.powershellgallery.com/packages/VMKeystrokes/1.0.0) from [William Lam](https://williamlam.com/2017/09/automating-vm-keystrokes-using-the-vsphere-api-powercli.html)\n\nYou can use the following cmdlet (on this order)\n\n- `Deploy-ArubaCPVm` Deploy CPPM OVA with add hard disk\n- `Set-ArubaCPVmFirstBoot` Configure first boot (Model, encrypt...)\n- `Set-ArubaCPVmSetup` Configure hostname, IP Address, NTP...\n- `Set-ArubaCPVmAddLicencePlatform` Add Licence Platform\n- `Set-ArubaCPVmUpdate` Update CPPM (using HTTP(S) or SSH)\n\na video will be online to see an example of auto deployement\n\n### MultiConnection\n\nFrom release 0.4.0, it is possible to connect on same times to multi ClearPass\nYou need to use -connection parameter to cmdlet\n\nFor example to get Static Host List of 2 CPPM\n\n```powershell\n# Connect to first ClearPass\n    $cppm1 = Connect-ArubaCP 192.0.2.1 -SkipCertificateCheck -DefaultConnection:$false\n\n#DefaultConnection set to false is not mandatory but only don't set the connection info on global variable\n\n# Connect to second ClearPass\n    $cppm2 = Connect-ArubaCP 192.0.2.2 -SkipCertificateCheck -DefaultConnection:$false\n\n# Get Static Host List for first ClearPass\n   Get-ArubaCPStaticHostList -connection $cppm1 | Format-Table\n\n  id name                description host_format host_type  value                 _links\n  -- ----                ----------- ----------- ---------  -----                 ------\n3001 SHL-list-IPAddress              list        IPAddress                        @{self=}\n....\n\n# Get Static Host List for second ClearPass\n   Get-ArubaCPStaticHostList -connection $cppm2 | Format-Table\n\n  id name                description host_format host_type  value                 _links\n  -- ----                ----------- ----------- ---------  -----                 ------\n3001 SHL-list-MACAddress             list        MACAddress                       @{self=}\n...\n\n#Each cmdlet can use -connection parameter\n```\n\n### Filtering\nFor `Invoke-ArubaCPRestMethod`, it is possible to use -filter parameter\nYou need to use ClearPass API syntax :\n\n|Description |\tJSON Filter Syntax |\n| ---------- | ------------------- |\n| No filter, matches everything | {} |\n| Field is equal to \"value\" | {\"fieldName\":\"value\"} or {\"fieldName\":{\"$eq\":\"value\"}} |\n| Field is one of a list of values | {\"fieldName\":[\"value1\", \"value2\"]}  or {\"fieldName\":{\"$in\":[\"value1\", \"value2\"]}} |\n| Field is not one of a list of values | {\"fieldName\":{\"$nin\":[\"value1\", \"value2\"]}} |\n| Field contains a substring \"value\" | {\"fieldName\":{\"$contains\":\"value\"}} |\n| Field is not equal to \"value\" | {\"fieldName\":{\"$ne\":\"value\"}} |\n| Field is greater than \"value\" | {\"fieldName\":{\"$gt\":\"value\"}} |\n| Field is greater than or equal to \"value\" | {\"fieldName\":{\"$gte\":\"value\"}} |\n| Field is less than \"value\" | {\"fieldName\":{\"$lt\":\"value\"}} |\n| Field is less than or equal to \"value\" | {\"fieldName\":{\"$lte\":\"value\"}} |\n| Field matches a regular expression (case-sensitive) | {\"fieldName\":{\"$regex\":\"regex\"}} |\n| Field matches a regular expression (case-insensitive) | {\"fieldName\":{\"$regex\":\"regex\", \"$options\":\"i\"}} |\n| Field exists (does not contain a null value) | {\"fieldName\":{\"$exists\":true}} |\n| Field is NULL | {\"fieldName\":{\"$exists\":false}} |\n| Combining filter expressions with AND | {\"$and\":[ filter1, filter2, ... ]} |\n| Combining filter expressions with OR | {\"$or\":[ filter1, filter2, ... ]} |\n| Inverting a filter expression | {\"$not\":{ filter }} |\n| Field is greater than or equal to 2 and less than 5 | {\"fieldName\":{\"$gte\":2, \"$lt\":5}} {\"$and\":[ {\"fieldName\":{\"$gte\":2}}, {\"fieldName\":{\"$lt\":5}} ]}\n\nFor `Get-XXX` cmdlet like `Get-ArubaCPNetwork`, it is possible to using some helper filter (`-filter_attribute`, `-filter_type`, `-filter_value`)\n\n```powershell\n# Get NetworkDevice named NAD-PowerArubaCP\n    Get-ArubaCPNetworkDevice -name NAD-PowerArubaCP\n...\n\n# Get NetworkDevice contains NAD-PowerArubaCP\n    Get-ArubaCPNetworkDevice -name NAD-PowerArubaCP -filter_type contains\n...\n\n# Get NetworkDevice where ip_address equal 192.168.1.1\n    Get-ArubaCPNetworkDevice -filter_attribute ip_address -filter_type equal -filter_value 192.168.1.1\n...\n\n```\nActually, support only `equal` and `contains` filter type\n\n### Disconnecting\n\n```powershell\n# Disconnect from the Aruba ClearPass\n    Disconnect-ArubaCP\n```\n\n# Issue\n\n## Unable to connect (certificate)\nif you use `Connect-ArubaCP` and get `Unable to Connect (certificate)`\n\nThe issue coming from use Self-Signed or Expired Certificate for switch management\n\nTry to connect using `Connect-ArubaCP -SkipCertificateCheck`\n\n# How to contribute\n\nContribution and feature requests are more than welcome. Please use the following methods:\n\n  * For bugs and [issues](https://github.com/PowerAruba/PowerArubaCP/issues), please use the [issues](https://github.com/PowerAruba/PowerArubaCP/issues) register with details of the problem.\n  * For Feature Requests, please use the [issues](https://github.com/PowerAruba/PowerArubaCP/issues) register with details of what's required.\n  * For code contribution (bug fixes, or feature request), please request fork PowerArubaCP, create a feature/fix branch, add tests if needed then submit a pull request.\n\n# Contact\n\nCurrently, [@alagoutte](#author) started this project and will keep maintaining it. Reach out to me via [Twitter](#author), Email (see top of file) or the [issues](https://github.com/PowerAruba/PowerArubaCP/issues) Page here on GitHub. If you want to contribute, also get in touch with me.\n\n\n# List of available command\n```powershell\nAdd-ArubaCPApiClient\nAdd-ArubaCPApplicationLicense\nAdd-ArubaCPAttributesMember\nAdd-ArubaCPDeviceFingerprint\nAdd-ArubaCPEndpoint\nAdd-ArubaCPLocaluser\nAdd-ArubaCPNetworkDevice\nAdd-ArubaCPNetworkDeviceGroup\nAdd-ArubaCPNetworkDeviceGroupMember\nAdd-ArubaCPRole\nAdd-ArubaCPStaticHostList\nAdd-ArubaCPStaticHostListMember\nConfirm-ArubaCPApiClient\nConfirm-ArubaCPApplicationLicense\nConfirm-ArubaCPEndpoint\nConfirm-ArubaCPLocalUser\nConfirm-ArubaCPNetworkDevice\nConfirm-ArubaCPNetworkDeviceGroup\nConfirm-ArubaCPRole\nConfirm-ArubaCPServerCertificate\nConfirm-ArubaCPService\nConfirm-ArubaCPStaticHostList\nConnect-ArubaCP\nConvert-ArubaCPCIDR2Mask\nDeploy-ArubaCPVm\nDisable-ArubaCPService\nDisconnect-ArubaCP\nEnable-ArubaCPService\nFormat-ArubaCPMacAddress\nGet-ArubaCPApiClient\nGet-ArubaCPApplicationLicense\nGet-ArubaCPAuthMethod\nGet-ArubaCPAuthSource\nGet-ArubaCPCertTrustList\nGet-ArubaCPClusterCertificate\nGet-ArubaCPCPPMVersion\nGet-ArubaCPDeviceFingerprint\nGet-ArubaCPEndpoint\nGet-ArubaCPEnforcementPolicy\nGet-ArubaCPEnforcementProfile\nGet-ArubaCPLocaluser\nGet-ArubaCPNetworkDevice\nGet-ArubaCPNetworkDeviceGroup\nGet-ArubaCPRole\nGet-ArubaCPServerCertificate\nGet-ArubaCPServerConfiguration\nGet-ArubaCPServerVersion\nGet-ArubaCPService\nGet-ArubaCPServiceCertificate\nGet-ArubaCPStaticHostList\nInvoke-ArubaCPRestMethod\nRemove-ArubaCPApiClient\nRemove-ArubaCPApplicationLicense\nRemove-ArubaCPAttributesMember\nRemove-ArubaCPEndpoint\nRemove-ArubaCPLocalUser\nRemove-ArubaCPNetworkDevice\nRemove-ArubaCPNetworkDeviceGroup\nRemove-ArubaCPNetworkDeviceGroupMember\nRemove-ArubaCPRole\nRemove-ArubaCPStaticHostList\nRemove-ArubaCPStaticHostListMember\nSet-ArubaCPAttributesMember\nSet-ArubaCPCipherSSL\nSet-ArubaCPEndpoint\nSet-ArubaCPLocalUser\nSet-ArubaCPNetworkDevice\nSet-ArubaCPNetworkDeviceGroup\nSet-ArubaCPRole\nSet-ArubaCPStaticHostList\nSet-ArubaCPuntrustedSSL\nSet-ArubaCPVmAddLicencePlatform\nSet-ArubaCPVmApiClient\nSet-ArubaCPVmFirstBoot\nSet-ArubaCPVmSetup\nSet-ArubaCPVmUpdate\nShow-ArubaCPException\n```\n\n# Author\n\n**Alexis La Goutte**\n- \u003chttps://github.com/alagoutte\u003e\n- \u003chttps://twitter.com/alagoutte\u003e\n\n# Special Thanks\n\n- Warren F. for his [blog post](http://ramblingcookiemonster.github.io/Building-A-PowerShell-Module/) 'Building a Powershell module'\n- Erwan Quelin for help about Powershell\n\n# License\n\nCopyright 2018 Alexis La Goutte and the community.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpoweraruba%2Fpowerarubacp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpoweraruba%2Fpowerarubacp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpoweraruba%2Fpowerarubacp/lists"}