Jump to content

Recommended Posts

Posted

We use wpa2 enterprise and radius authentication for our staff wireless network. Whenever we connect a laptop to this network, we get a message from Windows saying:

 

"Continue connecting? If you expect to find *our ssid* in this location, go ahead and connect. Otherwise, it may be a different network with the same name. Show certificate details"

and then it gives the option to Connect or Cancel.

 

We have a third party signed cert. Is there some way to push out this cert with Active Directory so that the laptops automatically trust this network? I have tried all kinds of things with no luck.

Thanks!

Posted

I’m unfamiliar with Radius on Windows as our Radius is BYOD tablets only.

 

But you can definitely push a cert out in GPO.

 

Policies, Security, Public Key, Trusted Root from memory, in some order or another.

Posted
We don't get this when connecting to one of the 50 Aruba aps on our site but we do with our 1 unifi ap in our office. Do you have a mix of APs? Maybe windows is being clever here and knows that our devices usually connect to a specific device brand.
Posted

We have a single SSID with multiple policies in NPS, for our domain joined laptops we use a certificate signed by the AD CA Servers which is automatically trusted and there is no warning message, however on our visitor/non-domain policy we use a third party signed certificate which does get this prompt. So I would imagine adding the certificate via GPO would solve this:

 

Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Public Key Policies

 

Not sure where you'd put it, ours go in Trusted Root CA but the certificate of the CA goes there, rather than of the NPS server.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...