Jump to content

Recommended Posts

Posted

Hello,

 

I have Radius authentication configured to only allow computers in the group "Domain Computers" join the network. This works fine for Windows devices joined to the domain.

 

I am wondering what to do about our growing iPad fleet. If I configure user authentication so users could join them to the network using their username and password. However there are 2 drawbacks.

1. I don't want them joining personal devices so how would I stop this?

2. I would rather the devices join without user input to reduce helpdesk tickets.

 

I am assuming I could use some kind of certificate based authentication and deploy the certificate via MDM? This is where there is a gap in my knowledge. I was wondering if someone could help fill in the blank please?

 

Thanks

 

PS: I don't want to use a Pre shared key for these iPads.

Posted

Thanks. It does seem a long way around the houses. Its not particle on a large scale deployment.

 

I have been looking into it more. I should be able to authenticate multiple devices with a single certificate. I need to do some more testing though.

 

Thanks

Posted

Our iPads are managed via Apple configurator. We created a separate ssid and used smoothwall radius to rather than windows nps.

 

All iPads use the same username/password. We used smoothwall as the deceives wasn’t one to one so used the ssl login page.

 

We also created our internal/guest on the iPads with rubbish details so they couldn’t connect.

 

Hopefully some of this may be useful.

 

Regards

 

Rob.

Posted

I've been testing this recently with RADIUS through NPS and iPads. I created a generic 'iPad User' in AD, and added that to the group which is also set in RADIUS to allow connection on the SSID I wanted it to connect e.g Student-Wifi.

 

I then had to export the certificate for the NPS server, and uploaded that, along with the iPad User credentials into a WiFi Payload in Profile Manager. Once the iPads picked up the new WiFi payload, they could connect to the wifi straight away. Without including the certificate, there is a prompt on the iPad asking if you would like to trust the server certificate.

 

I've only tested this so far, and is by no means the best way of doing it, however it did work. I would be interested to know if there is a better way to do it, or which certificate I should be using, if the server one is incorrect.

Posted
I would be interested to know if there is a better way to do it, or which certificate I should be using, if the server one is incorrect.

 

If the certificate is from an internal PKI (such as active directory certificate services) you should use push the root certification authority public certificate to the iPad. That way the iPad should trust any certificate issued by the Root CA (subordinate CAs, NPS, IIS webservers etc) without a prompt.

  • Thanks 1
  • 4 months later...
Posted

We've recently implemented a Xirrus solution at a primary school using RADIUS through NPS and i'm trying to get our iPads to connect seamlessly. I have created a generic account in AD which is also in the group that is allowed access via NPS, and I believe I have exported the correct certificate from the NPS server to the iPads via certificate upload however it fails to auto connect and when I try to connect manually it works but only after a prompt to trust the certificate. Ideally i'd like to get past this as the students are as young as 5 so its a tideous task for them and it seems staff too...

 

Any advice and guidance would be greatly appreciated.

Posted

I would check that you have the right certificate pushed out, as computer_expert says above, you can push the root CA certificate (the same one that goes to all the domain devices I believe), and that will trust any other certificates generated by the CA.

 

Do you use Apple Profile Manager or Xirrus to manage the iPads? You might also have to make sure that the profile for the WiFi is set up to use/trust the correct certificate, along with the generic credentials that you've entered.

Posted
I would check that you have the right certificate pushed out, as computer_expert says above, you can push the root CA certificate (the same one that goes to all the domain devices I believe), and that will trust any other certificates generated by the CA.

 

Do you use Apple Profile Manager or Xirrus to manage the iPads? You might also have to make sure that the profile for the WiFi is set up to use/trust the correct certificate, along with the generic credentials that you've entered.

 

Ahh okay so would I be right in saying that when I set NPS up and I set the certificate for PEAP etc. As a signed cert from one of our DCs... instead of using the one from our NPS server I should just use the one directly from the DC? We also use Lightspeed to manage our iPads, Xirrus is just our WiFi solution using RADIUS via NPS.

Posted

I think you can leave the PEAP certificate as the one for the NPS server, and if you deploy the Root CA certificate from your DCs to the iPads, then that will trust the NPS certificate automatically. Either should work though.

 

When I've tested this before with Apple Profile Manager, in the WiFi profile it has 2 settings, one for protocols where you set the PEAP settings and add in the username/password, and another for 'Trust' which is where you set the certificate for it to use. From within here you select the certificate to use, so just having the cert on the iPad won't work, you have to tell the WiFi profile to use it.

Posted
I would check that you have the right certificate pushed out, as computer_expert says above, you can push the root CA certificate (the same one that goes to all the domain devices I believe), and that will trust any other certificates generated by the CA.

 

Do you use Apple Profile Manager or Xirrus to manage the iPads? You might also have to make sure that the profile for the WiFi is set up to use/trust the correct certificate, along with the generic credentials that you've entered.

 

Right okay! One more question regarding that as i've just had a word with my manager about it and he had the same response that pushing the certificate from the DC would do it. We use PEAP and MSCHAP-V2 as authentication methods, now Lightspeed has that option available (PEAP) but looking at their documentation it seems to read that I need to have an SCEP server on my network dishing out the certificates... it seems like an awfully convoluted process just to automatically join the WiFi... am I going down a Rabbit hole with that, or is it necessary?

Posted
I don't think you need that if you have AD CS, you might need SCEP for individual device certificates, but with generic credentials and the Root CA then it should work fine. You've proved that you can join it manually from the device so your settings aren't that far out, just need to make sure the WiFi profile is using the right certificate. I've never used Lightspeed so can't advise any further on that.
Posted
I would check that you have the right certificate pushed out, as computer_expert says above, you can push the root CA certificate (the same one that goes to all the domain devices I believe), and that will trust any other certificates generated by the CA.

 

Do you use Apple Profile Manager or Xirrus to manage the iPads? You might also have to make sure that the profile for the WiFi is set up to use/trust the correct certificate, along with the generic credentials that you've entered.

 

That makes complete sense, i'll try using the Root CA and see if that gets it sorted. As you said it should be much simpler than using SCEP and NDES etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...