Jump to content

Recommended Posts

Posted

How do you all do it? We have two SSID's - BYOD and Guest. We need to push somehow the certificate down to the devices at login either prompting the user or it being done automatically.

 

We are using smoothwall, and i know they have a 'certificate' page but this is editable.

 

We are using Cambium wifi.

Posted
For our Ruckus Wifi, we've been getting SSL Certificates from JANET (which are only for 12 months these days) as there is no way for me to automate a LetsEncrypt certificate into the system
Posted (edited)

For BYOD and Guest I'd use public CA signed. For own devices there is a security case to use your own internal and distribute by MDM or group policy.

 

I have in the past put a link to a cert on a web server that the BYOD/Guest users could get to but was a bit of a faf.

Edited by Davit2005
Posted

Because they are not self signed certificated, we don't have to distribute them as they are authenticated by trusted providers already (for example our Wifi ones are Quovadis ones)

 

Or are you specifically referring to the SSL decyption/interception certificates more so than sign in page ones?

If so, we send our guest devices out via a non SSL proxy as it was too much trouble trying to get visitors to add in the RM certificate depending on the OS they were using, and if it was a manged device etc

Posted
How do you distribute the certificates?

 

Group Policy for managed Windows devices for Apple or others you may be able to use a MDM.

 

If you have a public CA signed cert then you should not need to. However if this is for decryption I do not think you can use public CA signed so only option would be to put a link where people can download if they are BYOD or Guest.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...