Jump to content

Recommended Posts

Posted

Hi all,

 

Was wondering if anyone has managed to get WPA2 Enterprise Authentication working with NPS.

 

I've been asked by the council to look at replacing the county wide WPA2 PSK for the schools wifi with Certificates.

 

We don't have a county wide AD, so we'd be running a server in county all who's sole job will be to authenticate the WPA2 requests.

 

I was under the impression you can set this up by using certificates, create 1 per school and issue that the schools to install on devices.

 

But I'm at a loss on how to get this working.

 

Managed to get the certificates, NPS installed, WPA2 SSID setup, RADIUS proxied to NPS from the Wifi points, but I can't get devices to connect to it.

 

Any help would be great

Posted

That's what I use, but not in the same way you describe. Our machines all use individual computer certificates from our AD's certificate authority. I believe this is how most people do it.

 

That said, who you've described sounds like it can be made to work. In my experience this tends to be more difficult to set up on the clients than on the server. If the certificate is in the user certificate store rather than computer store and the config is set to use computer configuration, it will fail. Or vice-versa. Can you describe how you've set the clients up and which store the cert is in?

Posted

There is no centralized AD, so each school usually has it's own AD.

 

The plan would be to install an AD at top level, create a user for each school, create a certificate for those users, give that certificate to the schools to install on devices (via Group Policy), then use Group Policy to connect to the WPA2 Network for internal Access.

 

Now I've managed to get certificates working (needed to log on as the user and create the certificate, I think I've missed some optional attributes that are needed in the certificate request), so that works, don't know if it works on a computer level yet though.

 

Separate SSID for BYOD, this is WPA2 Enterprise again, RADIUS requests are to a different IP, so use IP filtering on the connection request, NPS inspects the username, figures which school it came from (domain\username) and forwards the RADIUS request to the local schools RADIUS server.

  • 4 weeks later...
Posted (edited)

Be careful! It could easily be considered to be professionally negligent to deploy it with a certificate shared among all devices in a school if that is what you intend.

Nothing would be achieved over just using a PSK.

 

Ensure that you are using one certificate per device with individual enrolment, don't reuse credentials.

A primary purpose of WPA2-Enterprise is to get away from this aspect of WPA2-Personal.

It's a massive accountability, auditability and security nightmare waiting to happen otherwise.

Think about what would happen if you needed to revoke it, and the logistical steps required to correct and resolve it redistributing credentials.

 

You should have a certificate server per school to generate a certificate derived from that sites root on a per-device basis where you don't have federation.

Edited by nicklowe

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...