Jump to content

Recommended Posts

Posted (edited)

Hi,

 

With WPA3 becoming more common, and since Android 11+ removing the 'do not validate' on the certificate option when using RADIUS to connect to WiFi. How are you getting root CAs certificates onto devices, whether that is an internal CA or public CA such as GlobalSign? It also appears we need to specify the domain, or common name, on the certificate before a user can input their username and password to authenticate.

 

 

I understand the reasons why it behaves like this, I just wondered what others approach is to a) getting the CA cert on their devices, especially BYOD and b) configuring WiFi connection settings for users or is it as simple as just pointing them to a guide?

 

I guess, I'm almost wanting some form of SCEP setup for BYOD devices.

Edited by Manny-Tech
Posted (edited)

We use Eduroam and Profiles, prob won't be going 802.1x on our general wifi/BYOD in a hurry (people like connecting their games machines and other devices not 802.1x compatible in their accommodation) but when we start to do decryption on BYOD we will prob have some sort of link on a captive portal and the captive portal will use public certs.

 

Eduroam uses profiles so easy enough to distribute the cert through the profile.

Edited by Davit2005
Posted
Considering using publicly valid certs. Either LE if I can get reliable automation of RenewCert > Import to RADIUS server or pay £10/yr for a not-LE cert (but then have to deal with the daftness from vendors).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...