Jump to content

Recommended Posts

Posted

Storing wireless keys in keychain access util ?

 

Is there anyway to encrypt the wireless key so that it is not viewable so that we can add or allow students to use wireless without them being able to view the wep or wpa key ?

 

If they go into keychain access and view keychains they are able to go to the system section and double click on any of the added in wireless access points and tick the show password check box and it shows them the wep / wpa key which we do not want.

 

Any help much appreicated

 

Thanks

Posted (edited)

so they can work on there own laptops without using an ethernet port because there are no ethernet ports in the classroom bar maybe one or two but those are for the sims or staff machines.

 

side tracking a bit, anyway - is there a way of doing it so that the student can not access or view the wireless key via the keychain access util ?

Edited by gecko
Posted
so they can work on there own laptops without using an ethernet port because there are no ethernet ports in the classroom bar maybe one or two but those are for the sims or staff machines.

 

side tracking a bit, anyway - is there a way of doing it so that the student can not access or view the wireless key via the keychain access util ?

 

No, I don't think there is I'm afraid.

 

I think your only bet would be to introduce some form of network authentication, so that non-authorised machines couldn't connect even with the password.

 

Just a quick note, joining a laptop to the network which doesn't belong to the school could cause problems with the DPA. Do the SMT know about and support this?

  • Thanks 1
Posted
we have joined a quite a lot of students windows laptops and this is the first mac laptop that we have gotten with regards to joining to the network wirelessly, so am guessing so.
Posted

Hi Shane.

 

The Keychain files themselves are actually encrypted. The problems with your scenario are that:

 

1. The student *is* the administrator of the laptop

2. Therefore the student has the Keychain Password and can read the passwords stored in their account Keychain.

 

There isn't any way around this that I can think of so long as you aren't managing the machines via Open Directory. Sorry.

 

Now you would be best resetting the wireless encryption key and risking the onslaught, explaining that you can't give out the key securely. There needs to be some "edge" security to your network.

 

Take care,

 

Paul

Posted
Hi Shane.

 

The Keychain files themselves are actually encrypted. The problems with your scenario are that:

 

1. The student *is* the administrator of the laptop

2. Therefore the student has the Keychain Password and can read the passwords stored in their account Keychain.

 

There isn't any way around this that I can think of so long as you aren't managing the machines via Open Directory. Sorry.

 

Now you would be best resetting the wireless encryption key and risking the onslaught, explaining that you can't give out the key securely. There needs to be some "edge" security to your network.

 

Take care,

 

Paul

 

oh dear, indeed !

 

what do you mean by edge security ? What I did is I tried it with one of the wireless access points and then I deleted it completely out of key chain access and also made sure it wasn't in the network section in system prefs.

 

If we were to get os x server ( open directory ) have you got a guide on how we would do it ?

 

haven't heard from you in a while :) @ kingswood

Posted
oh dear, indeed !

 

what do you mean by edge security ? What I did is I tried it with one of the wireless access points and then I deleted it completely out of key chain access and also made sure it wasn't in the network section in system prefs.

 

If we were to get os x server ( open directory ) have you got a guide on how we would do it ?

 

haven't heard from you in a while :) @ kingswood

 

Edge security is some form of controlling device access to the network - such as NAC by cisco, or mac based filtering (which isn't actually that secure, it is just a deterant) or something like that.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...