Jump to content

Recommended Posts

Posted

Hi,

 

I am currently setting up a Radius BYOD Network for my staff to connect personal devices to and have them Authenticate with AD and account with smoothwall for notification purposes.

 

NPS is currently installed on our DC and working with authentication for laptops, iphones and older generation Android "pre version 11" any android 11 or newer will not connect.

 

When connecting with an iphone or laptop it asks to trust the server certificate and all works, Android 11 or newer flat out refuses to connect. When searching online it looks like we need to install the CA Certificate on the device but nothing has explained how to download the CA cert so we can import this into android. Any help would be greatly appreciated.

 

End Goal is to have personal devices connect to the WiFi and they can login with AD Credentials and get access to the Internet.

 

Thanks in advance.

 

A.

Posted
I host the CA cert on a web page that the students can access. It can then be downloaded on an Android phone, and can be installed and trusted at that point. There’s a couple of other faffy steps needed for it to all work (the particular settings in the wifi connection), that I can’t remember but I have them documented at work.
  • Thanks 1
Posted

Hi 3s-gtech,

 

This sounds exactly like what I am trying to set up, currently this will be for staff but will then be expanded for students to connect, Are you able to share the documentation you have? this will help me solve this issue i've been stuck on for some time going back and forth with our internet provider and smoothwall.

 

Hosting the CA cert ona webpage sounds like a great idea, i was wondering how to get this on student devices but hosting it on a easily accessible webpage makes sense.

 

Thank you.

 

A.

Posted

I’ll try to remember to put it all here. It works well, tested on lots of devices. Took me a while too, I had to sit and work it out over a day.

 

PM me to remind me, but I’ll put the instructions in this thread.

Posted
There's a reason BYOD is going the way of the dodo

 

I'd question this. This isn't a question of BYOD, it is a question of RADIUS on personal devices. DPSK works perfectly well with BYOD.

Posted

  1. Download the file
  2. Go to 'Settings' on your phone
  3. Choose 'Connections', then 'Wi-Fi', then the three dots and 'Advanced'
  4. Click on 'Install network certificates'
  5. Select the menu icon in the top right then 'Internal Storage'
  6. Choose the certificate file from the folder you saved it to (Downloads usually).
  7. Click Done and call it School_CA
  8. Connect to the network 'yourBYODSSID'
  9. When asked for username ('Identity') enter username@domain
  10. When asked for a password enter your password (the same one you use for the computers)
  11. Click on CA certificate and chose School_CA
  12. Type 'yourFQDN' in the Domain box
  13. Click Connect
  14. It may be slow to connect - be patient!

Posted (edited)

We’ve been able to make it work without any need to download the NPS certificate to student devices. We’ve tested it working with either a Public NPS certificate or with the NPS server cert generated from the CA.

 

If their Android phone still has the option, select:

CA certificate: Don’t validate

 

If they don’t have that option (usually on Android 11+), select:

CA certificate: Use system certificates or Use installed certificates (same setting but named differently on some phones)

Online certificate status: Don’t validate

Domain: yourdomain.com or ad.your domain.com

 

We’ve also had a few newer Android phones like the Google Pixel’s pre-fill the word ‘anonymous’ in the ‘anonymous identity’ field, which users have to clear out to be able to connect or it fails with Reason Code 8 ‘The specified user account does not exist’.

Edited by georgeescott
Posted
Thanks everyone for your quick responses, How can I get the CA Cert from the server? this is where I am currently getting stuck, does anyone have a guide on how to export the CA Cert that works with android devices?
  • 6 months later...
Posted
I'm having exactly this issue with Android devices. To those of you who've resolved it, which server do I need the certificate from? Is it from the NPS server or a DC or another one?
Posted
Those of you using Samsung devices may find it works without having to put a certificate on it where as Google Pixel's dont as they are following security properly just incase anyone is caught out.
Posted
We’ve been able to make it work without any need to download the NPS certificate to student devices. We’ve tested it working with either a Public NPS certificate or with the NPS server cert generated from the CA.

 

If their Android phone still has the option, select:

CA certificate: Don’t validate

 

If they don’t have that option (usually on Android 11+), select:

CA certificate: Use system certificates or Use installed certificates (same setting but named differently on some phones)

Online certificate status: Don’t validate

Domain: yourdomain.com or ad.your domain.com

 

We’ve also had a few newer Android phones like the Google Pixel’s pre-fill the word ‘anonymous’ in the ‘anonymous identity’ field, which users have to clear out to be able to connect or it fails with Reason Code 8 ‘The specified user account does not exist’.

Thanks for this - I'm not super familiar with Android and that hasn't helped trying to streamline the BYOD people connecting. I got someone to test however, and this was the response;

 

Option 1 - Dont validate - Lets me connect to the AP but there is no internet when trying to browse the webOption 2 - Use system certificates - Does not let me connect to the AP

Andriod version - 14

One UI version - 6.1

 

Anything that's been missed? Thanks

Posted

I'm still trying to get this resolved. When I connect an apple device it asks me to trust a certificate from our network so I'm guessing that's the one I need to add to android devices.

 

The new problem I've got is that when I try to install the exported certificate on to a android mobile it says "Private Key required to install". This makes sense but when I export the certificate from the server the option to include the private key is greyed out. My googleing this morning hasn't found any way of exporting the private key with the certificate. Has anyone got any ideas of how I can get the certificate with the key to import on to a mobile?

Posted
I'm still trying to get this resolved. When I connect an apple device it asks me to trust a certificate from our network so I'm guessing that's the one I need to add to android devices.

 

The new problem I've got is that when I try to install the exported certificate on to a android mobile it says "Private Key required to install". This makes sense but when I export the certificate from the server the option to include the private key is greyed out. My googleing this morning hasn't found any way of exporting the private key with the certificate. Has anyone got any ideas of how I can get the certificate with the key to import on to a mobile?

 

Pretty sure You need the root cert not the server cert.

Posted (edited)

We fixed this by buying a trusted third-party ssl cert for our NPS host that, and making sure that the identity and anonymous identity fields both have the users username - without the cert the androids refused to join/were flaky/had other random issues and without the anonymous identity also having the user name with some androids this caused authentication failure. Now we have the a trusted cert for the NPS server, make sure to put the username in twice we have no issues. Once the device is connected we then install the MITM cert on the smoothwall via http://smoothwall-IP/getmitm

 

We did try a wildcard ssl cert we already owned but the Androids also didn't like this cert, had to have the hostname in the cert. Don't think we pay a lot for the cert each year

Edited by ThomL
  • Thanks 1
Posted
Get yourself a publicly trusted cert for each server hosting NPS. CN should be the FQDN of the server, install into the local computer personal certificate folder and use that with your policies in NPS. Found this resolves all Android 11+ / ChromOS device connection issues around trust.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...