Jump to content

Recommended Posts

Posted

Morning.

 

I've bought 5 Unifi NanoHD APs to play with as a possible upgrade route for our Ruckus that is getting old.

 

We want to use Radius so i've got Server 2012 R2 installed with NPS up and running.

 

It all worked fine last week, with the builtin certificate, but obviously iOS doesn't trust the builtin certificate so prompts the user to trust it. I'm trying to get it working without any cert prompt.

 

I've installed and generated our CA domain certificate and pushed that to the iPads via MDM, and I can see that appearing on the iPad. Because it's gone via MDM, it's already set to "Enable full trust for root certs" by default.

 

I've then generated a cert from our CA for the UniFi NPS server and selected it within NPS > Network Policies > Constraints > Microsoft PEAP.

 

When you connect an iPad to the UniFi SSID, it prompts for credentials correctly then prompts to trust the UniFi NPS Cert - but it is signed by our CA which the iPad already trusts.

 

Should it not just trust the NPS cert??

 

If I trust the cert, the iPad is authorised and both UniFi and Smoothwall see the iPad with username so Radius itself is working - it's just the iPad is always prompting to trust a cert?

 

Any guidance appreciated.

 

(I've also tried our GoDaddy wildcard, with intermediate certs installed, and our GoDaddy 5UCC, and got a 90day free Comodo cert yesterday, all of which are throwing EAP errors - but I suspect that's because although NPS responds to Unifi.mydomain.com internally, the actual server name is unifi.internal.domain which can't be entered in a public cert)

 

Peter

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...