Jump to content

Recommended Posts

Posted

At the moment, we deploy a PSK based wireless network to all our Chromebooks, but when we have our new wireless network installed this summer I would like to transition them all to an 802.1x based network.

 

Does anyone have any guidance for doing this?

 

I know I can set up a service account and deploy 802.1x that way, but that seems to miss the point of 802.1x?

Posted
I am half guessing as it’s been 5 years since I have managed Chromebook’s but could you do it using certificates? If they are pushed via the management console all existing devices will receive it. New devices could be enrolled via Ethernet and receive the certificate?
Posted (edited)
It's also been a while since I last did this. So, from the top of my head, the service account provides wifi access pre-authentication for devices that have not been logged into, not for userspace 802.1x. The configuration is done in google workspace and you can setup a new network with $USER or $USERID and $PASSWORD. As soon as the user logs in the wifi disconnects and passes the credentials to the userspace wifi . The user then logs into that network automatically. It's pretty seamless. IIRC we used EAP-TLS against freeradius - it's tiny enough to run a couple as containers in front of a loadbalancer, and the containers are ephemeral so it's easy to scale with load. Edited by dmj
  • 3 weeks later...
Posted
If your using a browser based safeguarding extension, do you need to authenticate the user onto the WiFi? Just a consideration. Our Chromebooks use the Smoothwall extension, which picks up the Azure AD Groups.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...