Jump to content

Recommended Posts

Posted

A number of my students have picked up the ios 16 beta release on our iPad 1:1 device scheme. These device will no longer join our 802.1x radius auth network. They will join a shared key network. All iOS 15 devices remain unaffected, and rolling back the device to iOS 15 solves the problem.

 

Our setup is a unifi network using window NPS on server 2016 as the radius auth server.

 

Has anyone else discovered this issue and a possible solution? I wonder if it's the self signed cert (that has an expired of 2029) on the radius server, but have not yet been able to test this.

 

I can use the mdm to hold back the devices on iOS15 to limit the impact when iOS 16 goes general release. But as the devices are a mixture of school provided devices and some BYOD apple devices I can't fully mitigate this. As you know rolling back iOS version once its on general release is practically impossible.

 

If anyone could share their experiences that would be great, even if it's report no issues on iOS16 with radius (then I atleast know its possible)

Posted

I’d be surprised if it’s not the self-signed cert. It’s becoming an issue on our RADIUS secured SSID, on newer Android devices. iOS will follow.

 

Our actual ‘internal’ SSID is still PSK.

Posted
This is going to be interesting if it is self signed cert issue. There are advantages to using self signed certs for Radius 802.1x.

 

Some devices only like certs that don't last longer than 13 months too, that has been a known issue for a while.

 

398 days is the limit for publicly trusted certs.

 

I wouldn’t use self signed anymore. It’s pointless.

  • 3 weeks later...
Posted

Hi all,

 

I have been facing this problem with iOS 16.0.2 as well. Some Novell eDirectories and one O365 AD were registered in ldap settings and using WPA2 EAP-TTLS connection with self-signed certificate.

We are using Freeradius 3.0.21 on openSUSE Leap 15.3.

 

In the radius log, I can see some unfinished EAP sessions:

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

!! EAP session with state 0x7f352f727f363ab6a457a9fad0de3e3d did not finish! !!

!! Please read http://wiki.freeradius.org/guide/Certificate_Compatibility !!

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

 

When the client tried to connect with/without certificate, the User-Password attribute wasn't sent.

 

(3062) Found Auth-Type = ldap-ksze

(3062) # Executing group from file /etc/raddb/sites-enabled/inner-tunnel

(3062) Auth-Type ldap-ksze {

(3062) ksze: WARNING: You have set "Auth-Type := LDAP" somewhere

(3062) ksze: WARNING: *********************************************

(3062) ksze: WARNING: * THAT CONFIGURATION IS WRONG. DELETE IT.

(3062) ksze: WARNING: * YOU ARE PREVENTING THE SERVER FROM WORKING

(3062) ksze: WARNING: *********************************************

(3062) ksze: ERROR: Attribute "User-Password" is required for authentication

(3062) [ksze] = invalid

(3062) } # Auth-Type ldap-ksze = invalid

(3062) Failed to authenticate the user

(3062) Using Post-Auth-Type Reject

(3062) # Executing group from file /etc/raddb/sites-enabled/inner-tunnel

(3062) Post-Auth-Type REJECT {

(3062) attr_filter.access_reject: EXPAND %{User-Name}

(3062) attr_filter.access_reject: --> maupet

(3062) attr_filter.access_reject: Matched entry DEFAULT at line 11

(3062) [attr_filter.access_reject] = updated

(3062) update outer.session-state {

(3062) &Module-Failure-Message := &request:Module-Failure-Message -> 'ksze: Attribute "User-Password" is required for authentication'

(3062) } # update outer.session-state = noop

(3062) } # Post-Auth-Type REJECT = updated

(3062) Login incorrect (ksze: Attribute "User-Password" is required for authentication): [maupet/] (from client WLC port 8 cli 76-08-32-d8-e4-9e via TLS tunnel)

(3062) } # server inner-tunnel

(3062) Virtual server sending reply

(3062) eap_ttls: Got tunneled Access-Reject

(3062) eap: ERROR: Failed continuing EAP TTLS (21) session. EAP sub-module failed

(3062) eap: Sending EAP Failure (code 4) ID 10 length 4

(3062) eap: Failed in EAP select

(3062) [eap] = invalid

(3062) } # Auth-Type eap = invalid

(3062) Failed to authenticate the user

(3062) Using Post-Auth-Type Reject

(3062) Post-Auth-Type sub-section not found. Ignoring.

(3062) Login incorrect (eap: Failed continuing EAP TTLS (21) session. EAP sub-module failed): [maupet/] (from client WLC port 8 cli 76-08-32-d8-e4-9e)

(3062) Delaying response for 1.000000 seconds

Waking up in 0.1 seconds.

Waking up in 0.7 seconds.

(3062) Sending delayed response

(3062) Sent Access-Reject Id 30 from 193.225.81.36:1812 to 10.63.128.3:41419 length 44

(3062) EAP-Message = 0x040a0004

(3062) Message-Authenticator = 0x00000000000000000000000000000000

Waking up in 5.7 seconds.

(3057) Cleaning up request packet ID 25 with timestamp +416818

(3058) Cleaning up request packet ID 26 with timestamp +416818

(3059) Cleaning up request packet ID 27 with timestamp +416818

(3060) Cleaning up request packet ID 28 with timestamp +416818

(3061) Cleaning up request packet ID 29 with timestamp +416818

Waking up in 0.1 seconds.

(3062) Cleaning up request packet ID 30 with timestamp +416818

Ready to process requests

 

It's only on iOS 16, no issues below this and neither with Android and Windows clients.

Posted
Do we need to stage an intervention, or has there been a renaissance that's past me by?

 

Yeah, I know... It is one of my client who cannot migrate the old Novell structure to MS AD now...

But the authentication with O365 user is not work as well.

The connection between radius and O365 LDAP is implemented with PAP not MSCHAPV2. They had to choose EAP-TTLS (PAP) due to Novell eDir...

Posted (edited)

We are having issue as well with 802.1x and iOS 16+. Works perfectly on iOS 15. If we connect without using the MDM, so supplying a username and password, it will connect. As soon as we manage the device with an MDM, the issue starts, but on some device, after a few "trust certificate", no where, we receive an iOS message saysing this wifi needs to authorize a certificate (not asking for trust but to accept).

 

Certificate is supplied by the Radius server, which is an internal certificate (we are our own CA).

 

 

What’s new for enterprise in iOS 16 - Apple Support

 

This must be related to this I guess:

 

Device Management

 

  • Managed Device Attestation uses the Secure Enclave and cryptographic attestations to secure communications by managed devices when connecting to services such as MDM, VPN, and 802.1X.

My guess would be that we need to add the trust root / sub CA to the MDM for that particular certificate, but for now, we have tickets opened with MDM and Apple. I do think there is multiple issue with Enterprise Wifi on iOS16...

Edited by ChristTheGreat
Posted
What’s this Novell you speak of ?

 

I wouldn’t use self signed certificates anymore. Best to use publicly trusted certs.

 

There is a Novell LDAP directory what contains all workers.

But the structure is a bit complicated. There are several OUs in the same LDAP directory, so I had to add each OUs to the sites-available/ldap configuration.

I have tested with ldapsearch and the radtest, and the users were found, so it works well.

 

However It seems to be solved the iOS16 issue. I created a new .mobileconfig with the WPA2-enterprise network and I have added the server cert and attached to it. Now it started to work...

 

If I add public cert to radius server, the client will trust it automatically or I need to add manually to the client as well?

  • 3 weeks later...
Posted

We are also having this issue. My NPS server's certificate is 12 months period so that is apparently not a fix for us.

The radius server presents it certificate, but the device will not allow us to trust it. Has anyone found any other workarounds?

Posted
We are still having small issues with this, some devices simple will not connect to the 802.1X student wifi. If i create a new wifi with a different name and identical settings (the same NPS server, certs etc) it will work. If i factory reset the device it will begin on the student wifi. BUT If i restore it from iCloud backup it still wont work. Its like there is a dodgy wifi profile stuck on the device. Ive tried the reset network settings etc, all that seems to work that i can find is a factory reset without restore from backup

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...