synaesthesia Posted April 25, 2019 Posted April 25, 2019 Hi all, Schools Broadband's documentation is very lax when it comes to actual details of setting up Netsweeper or migrating to it, and still waiting a response to a query regarding mobile devices. How *exactly* are people setting up certificates for mobile devices? SB's documentation tells you to go to a settings page and look at something.... and that's it. (Thanks!) So for mixtures of android and ios devices, there are mumblings of wpad.dat being used (argh for crying out loud REALLY, feels like going back in time) but I don't see how that's certificate related? Have I missed something?
sted Posted April 25, 2019 Posted April 25, 2019 if you have an mdm you can deploy it with that. for random devices i just create a web page with a link to the certificate and usually end up doing it manually with the device owner watching (or showing a sensible person how to do it (im only in most schools a few hours a week))
synaesthesia Posted April 25, 2019 Author Posted April 25, 2019 Yeah, same for us; the android devices (ugh, hudls) aren't on any MDM which makes it fun, plus they're central so will all have to be done in the few available hours on site!
synaesthesia Posted May 1, 2019 Author Posted May 1, 2019 Ugh, this seems counter-intuitive > So, school newly on Netsweeper, someone comes in and connects to the school's wireless (basic Unifi system with half a dozen APs). Everything whinges because of certificate. How on earth does one provide said certs to guest devices for them to install?
Arthur Posted May 1, 2019 Posted May 1, 2019 How on earth does one provide said certs to guest devices for them to install? We have installers for our certs on an externally accessible webpage with an .htaccess that only allows access from the BYOD network. It works well. 1
snagrat Posted May 1, 2019 Posted May 1, 2019 We have a page that redirects directly to SB’s where they host the certificate. Users just join WiFi, go to ca.website.com and the certificate downloads 2
Edu-IT Posted May 1, 2019 Posted May 1, 2019 As above, certificates on a website with instructions on how to install. 1
ibpalle Posted May 3, 2019 Posted May 3, 2019 Since BYOD devices aren't managed, getting a CA on those devices is all about availability. Web page with download and instructions on how to install - with a link redirect from blockpage is part of what Smoothwall does. The web page can be hosted on other locations as well. Instructions can be copied to an email with the ca as attachment and sent out in intro e-mail to students. Link on homepage to a download and install info page. As many options as possible to make it as easy for the users to find.
IrritableTech Posted May 3, 2019 Posted May 3, 2019 You could turn of decryption for Guest devices? No cert required then. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now