Manny-Tech Posted October 4, 2023 Posted October 4, 2023 (edited) Hi, With WPA3 becoming more common, and since Android 11+ removing the 'do not validate' on the certificate option when using RADIUS to connect to WiFi. How are you getting root CAs certificates onto devices, whether that is an internal CA or public CA such as GlobalSign? It also appears we need to specify the domain, or common name, on the certificate before a user can input their username and password to authenticate. I understand the reasons why it behaves like this, I just wondered what others approach is to a) getting the CA cert on their devices, especially BYOD and b) configuring WiFi connection settings for users or is it as simple as just pointing them to a guide? I guess, I'm almost wanting some form of SCEP setup for BYOD devices. Edited October 4, 2023 by Manny-Tech
Davit2005 Posted October 5, 2023 Posted October 5, 2023 (edited) We use Eduroam and Profiles, prob won't be going 802.1x on our general wifi/BYOD in a hurry (people like connecting their games machines and other devices not 802.1x compatible in their accommodation) but when we start to do decryption on BYOD we will prob have some sort of link on a captive portal and the captive portal will use public certs. Eduroam uses profiles so easy enough to distribute the cert through the profile. Edited October 5, 2023 by Davit2005
pete Posted October 5, 2023 Posted October 5, 2023 Considering using publicly valid certs. Either LE if I can get reliable automation of RenewCert > Import to RADIUS server or pay £10/yr for a not-LE cert (but then have to deal with the daftness from vendors).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now