mac_shinobi Posted January 25, 2008 Posted January 25, 2008 Storing wireless keys in keychain access util ? Is there anyway to encrypt the wireless key so that it is not viewable so that we can add or allow students to use wireless without them being able to view the wep or wpa key ? If they go into keychain access and view keychains they are able to go to the system section and double click on any of the added in wireless access points and tick the show password check box and it shows them the wep / wpa key which we do not want. Any help much appreicated Thanks
localzuk Posted January 25, 2008 Posted January 25, 2008 It prompts me for an administrator account when I do this...
mac_shinobi Posted January 25, 2008 Author Posted January 25, 2008 The student owns the laptop and has admin privs so if she found out about keychain the student could easily enter in the admin password to display the wireless key
Domino Posted January 25, 2008 Posted January 25, 2008 then why are you letting her attach it to your wireless?
mac_shinobi Posted January 25, 2008 Author Posted January 25, 2008 (edited) so they can work on there own laptops without using an ethernet port because there are no ethernet ports in the classroom bar maybe one or two but those are for the sims or staff machines. side tracking a bit, anyway - is there a way of doing it so that the student can not access or view the wireless key via the keychain access util ? Edited January 25, 2008 by gecko
localzuk Posted January 25, 2008 Posted January 25, 2008 so they can work on there own laptops without using an ethernet port because there are no ethernet ports in the classroom bar maybe one or two but those are for the sims or staff machines. side tracking a bit, anyway - is there a way of doing it so that the student can not access or view the wireless key via the keychain access util ? No, I don't think there is I'm afraid. I think your only bet would be to introduce some form of network authentication, so that non-authorised machines couldn't connect even with the password. Just a quick note, joining a laptop to the network which doesn't belong to the school could cause problems with the DPA. Do the SMT know about and support this? 1
Domino Posted January 25, 2008 Posted January 25, 2008 DPA = Data protection Act SMT = Senior Management Team
mac_shinobi Posted January 25, 2008 Author Posted January 25, 2008 we have joined a quite a lot of students windows laptops and this is the first mac laptop that we have gotten with regards to joining to the network wirelessly, so am guessing so.
gaz350 Posted January 25, 2008 Posted January 25, 2008 you also now have the problem of this password being passed around and now anyone can bypass you to join your network (not good!!)
mac_shinobi Posted January 25, 2008 Author Posted January 25, 2008 you also now have the problem of this password being passed around and now anyone can bypass you to join your network (not good!!) 2nd you on the "not good!"
kingswood Posted January 26, 2008 Posted January 26, 2008 Hi Shane. The Keychain files themselves are actually encrypted. The problems with your scenario are that: 1. The student *is* the administrator of the laptop 2. Therefore the student has the Keychain Password and can read the passwords stored in their account Keychain. There isn't any way around this that I can think of so long as you aren't managing the machines via Open Directory. Sorry. Now you would be best resetting the wireless encryption key and risking the onslaught, explaining that you can't give out the key securely. There needs to be some "edge" security to your network. Take care, Paul
mac_shinobi Posted January 26, 2008 Author Posted January 26, 2008 Hi Shane. The Keychain files themselves are actually encrypted. The problems with your scenario are that: 1. The student *is* the administrator of the laptop 2. Therefore the student has the Keychain Password and can read the passwords stored in their account Keychain. There isn't any way around this that I can think of so long as you aren't managing the machines via Open Directory. Sorry. Now you would be best resetting the wireless encryption key and risking the onslaught, explaining that you can't give out the key securely. There needs to be some "edge" security to your network. Take care, Paul oh dear, indeed ! what do you mean by edge security ? What I did is I tried it with one of the wireless access points and then I deleted it completely out of key chain access and also made sure it wasn't in the network section in system prefs. If we were to get os x server ( open directory ) have you got a guide on how we would do it ? haven't heard from you in a while @ kingswood
localzuk Posted January 26, 2008 Posted January 26, 2008 oh dear, indeed ! what do you mean by edge security ? What I did is I tried it with one of the wireless access points and then I deleted it completely out of key chain access and also made sure it wasn't in the network section in system prefs. If we were to get os x server ( open directory ) have you got a guide on how we would do it ? haven't heard from you in a while @ kingswood Edge security is some form of controlling device access to the network - such as NAC by cisco, or mac based filtering (which isn't actually that secure, it is just a deterant) or something like that.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now