Jump to content

Recommended Posts

Posted

Hi

 

https://www.xda-developers.com/android-11-break-enterprise-wifi-connection/

 

The IT department have had a few android devices facing the problem in the article above. We have a google Pixel4a in the IT office using for testing purposes to try work around this issue. I am aware of onboarding solutions that will be a solution to this such as Aruba onboarding. However first we would like to explore the options of manually configuring this with a work around.

 

This is what we have done so far:

 

1. Exported root certificate on the radius server

2. Download and install as WIFI certificate on the phone.

3.Connect to SSID using the following settings:

 

EAP method: PEAP

 

Phase 2 authentication: MSCHAPV2

 

CA certificate: Select root certificate installed

 

Online Certificate Status: Do not Validate

 

Domain: domain name

 

Identity: My username

 

Anonymous identity: Blank

 

Password: my password

 

 

Unfortunately it is still failing to connect. Is there anything you guys think I have missed?

 

Many thanks,

 

Aled

Posted
Had exactly the same issue here. Think we managed to find a workaround by adding the network manually and using your normal settings. Not sure why it works that way and not when you just tap on the network but just android things... [h=1]¯\_(ツ)_/¯[/h]
Posted (edited)
In our case for certain Android device we have them install our CA certificate on their device as a 'wifi' certificate. They can then select it from the CA certificate dropdown box and they're then able to connect, I think I do have them put something in the validation box though. Edited by chris11256
Posted

Many thanks for the advice above. I have installed the CA as a Wi-Fi certificate and also tried to configure a network manually as suggested above. Still no joy. Such a frustrating issue.

 

Many thanks

 

Aled

Posted

Android 11, currently on the latest pixel phones, has removed the feature to not inspect CA certificates.

You will have to install the certificate beforehand. You can then choose the CA on the second drop down.

 

This is the first model / carrier to start this. It is only going to become more wide spread.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...