synaesthesia Posted March 22, 2024 Posted March 22, 2024 Tearing my hair out with BYOD on Smoothwall. It's working well for iDrones and older Androids, but Android 13 devices are just having none of it. You can't "not validate" the certificate on these, and even trying to import the CA certificate directly, there's no attempt at connection. I don't even know what to put in the "domain" field on the Android, as there isn't a domain in the CA. Fairly standard RADIUS setup with Smoothwall, PEAP and MSCHAP auth. Smoothwalls documentation only says anything about the now defunct "Do not validate" option Any hints/gotchas on this ?
ITGuyNW Posted March 22, 2024 Posted March 22, 2024 Only thing I can tell you is that when you try and connect, take the word anonymous out of the anonymous field. Apparently its a bug. If I do that, I can connect. 1
smarties11 Posted March 22, 2024 Posted March 22, 2024 Tearing my hair out with BYOD on Smoothwall. It's working well for iDrones and older Androids, but Android 13 devices are just having none of it. You can't "not validate" the certificate on these, and even trying to import the CA certificate directly, there's no attempt at connection. I don't even know what to put in the "domain" field on the Android, as there isn't a domain in the CA. Fairly standard RADIUS setup with Smoothwall, PEAP and MSCHAP auth. Smoothwalls documentation only says anything about the now defunct "Do not validate" option Any hints/gotchas on this ? Haven't got any advice for you I'm afraid, but we see the same problem here. Thankfully we don't have too many staff with newer Androids and those that have for now we have given them a captive portal password on our visitor SSID. It's only my list of things to investigate. This is the one thing that Apple have right IMHO - our apple users simply enter a username and password, hit 'trust' on the cert and job done. No messing around with setting do not validate and making sure username is in the identity field etc. I still hate Apple though 🤣 1
Lee2807 Posted March 22, 2024 Posted March 22, 2024 We have a similar setup (Ruckus, Smoothwall and freeradius) Android 13 devices can be very difficult. We import the CA certificate for the CA that signs the radius cert before attempting to join. For domain when joining on an Android device we use the CN attribute of the CA cert. This does seem important if we don't fill in the domain field correctly the join fails. 2
CrootUK Posted March 22, 2024 Posted March 22, 2024 we use a public/signed cert from comodo on our radius servers due to this, we just enter the cert domain in domain field and it just works.
timbo343 Posted March 22, 2024 Posted March 22, 2024 (edited) Tearing my hair out with BYOD on Smoothwall. It's working well for iDrones and older Androids, but Android 13 devices are just having none of it. You can't "not validate" the certificate on these, and even trying to import the CA certificate directly, there's no attempt at connection. I don't even know what to put in the "domain" field on the Android, as there isn't a domain in the CA. Fairly standard RADIUS setup with Smoothwall, PEAP and MSCHAP auth. Smoothwalls documentation only says anything about the now defunct "Do not validate" option Any hints/gotchas on this ?BYOD MitM on Android devices is no more or you have to accept the "no internet connection" issue. The issue is Android 13 and 14 need to connect to google.com or *.google.com which then breaks search term filtering so BYOD should only be DNS filtering now and list it on a risk register. At the end of the day, users could just tether their own devices to their phones or use data on their phones. Edited March 22, 2024 by timbo343
synaesthesia Posted March 25, 2024 Author Posted March 25, 2024 At the end of the day, users could just tether their own devices to their phones or use data on their phones. Aware, although irritated as it works fine for crapple users. And that last bit - true for most places, however here is the Bermuda Triangle of Phone Signal
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now