Jump to content

Recommended Posts

Posted (edited)

I have a mac mini that sits on the shelf in my server room purely for the purposes of broadcasting airplay printers on my network for papercut so iOS devices can print. As i have a 1:1 VLAN and a curriculum VLAN i use the Ethernet adapter to connect to my curriculum network and the wifi adapter to connect to my student 1:1 network. I could never get the zone bridging on the smoothwall to pass airprinter from one vlan to the other and this solution has worked fine for about 2 years. I think the issues is similar to that of trying to zone bridge apple tv's, it cant be done without bonjour gateway.

 

So i though i could get abit more value out of the mac mini by installing the OSX server utilities on it and making it into an apple caching server as on monday im deploying another year group of ipads which inevitably will result in minimal remaining internet bandwidth.

 

So the 1st issue was that it was still on Yosemite so i couldn't install the OSX server utilities from the app store. So i upgraded it to El Capitan installed OSX server utilities on it (paying £14.99 for the pleasure) enabled apple caching, added a zone bridging rule to the smoothwall so that the devices on the 1:1 vlan can access the IP of the Ethernet port that was bound to the apple caching system as per some other edugeek thread i found. Why you can't bind apple caching services to a DNS name is a mystery as this would have simplified things with a few static DNS entries. Anyway the zonebridging will have to do.......All is good in the world....except i haven't tested it because im at home watching cash in the attic while i do it (testing is friday's job.)

 

And then i realized that the wifi adaptor on the mac mini is no longer connected, so i though the update to EL Capitan must have lost the pass key or something. So i re-entered it and it INSTANTLY rejected the connection.

 

Much googling later i have discovered that with the release of EL Capitan they have tighten up on the security requirements of 802.1x connections. It will now no longer accept 802.1x CA certs that are less than 512bit. Ive check mine and is 1024bit and it will only accept TLS 1.2 connection. My Firmware on the ruckus is patched as high as is available.

 

In the end i managed to resolve this by stripping out all traces of the 802.1 cert and login details from keychain and manually adding the 802.1 cert to the system section and manually trusting it. After a reboot it decided it would connect to the radius connection.

 

Anyway the point to this tread is that if you find yourself faced with the requirement to update to El Capitan and use a 802.11 wifi connection.....dont just dive in, you'll need to check the spec of your radius cert and your wifi's ability to support TLS 1.2

Edited by stgoodyeara

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...