Jump to content

Recommended Posts

Posted

Starting to have a few more issues with PEAP authentication with newer Android versions and Samsung devices. Up to, I believe, Android 15 it seems quite easy - forgo the CA certificate, provide username and password and remove "anonymous" from the anonymous identity and everything connects hunky dory.

Iphones are even less hassle - username, password, trust the smoothwall certificate. end of. However on newer devices and Samsungs, it won't progress without either using a system certificate or installing one, adding yet another step.

It's easy to say I'd love to ditch BYOD and I still think it's days are numbered but mobile signal round here is non existent. I'd also love to be able to leverage the options in Cambium but.... we all know why that's probably not worth pursuing at the moment.

So for certificates, what exactly are others doing please?

I've tried using system certificate and our local domain but that doesn't work, and not a clue what actual certificate to provide for connecting in the first place. Documentation to this effect seems to be all over the shop and my brain hurts :D

 

Posted

There was an issue in Pixel phones where they dropped the ability to "do not validate" this appears to have been fixed as now they off a Trust on First Use option which will allow you to use a self signed cert and agree to to when connecting much like iOS does. We are seeing this on recent Pixels and Samsungs. So we make sure that the user has the latest update on their phone and this usually works.

  • Like 1
Posted

We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. 

The other route is enrol in an MDM... 

i can share instructions from pre-CloudPath if it helps? Again they were reasonably vague though to try to cover the majority of devices without taking into account the specific variations.

Cheers

  • Like 1
Posted

Cheers, no worries - I did see the Trust on First Use option on the Android 16 device I was trying this morning, but it didn't seem to work. I didn't spend much time on it though, so I'll grab it later.

MDM is out of the question, these are personal devices. With luck the cambium setup gets sorted out and I'll make use of easypass which will allow SSO via Google :)

Posted
15 minutes ago, synaesthesia said:

Cheers, no worries - I did see the Trust on First Use option on the Android 16 device I was trying this morning, but it didn't seem to work. I didn't spend much time on it though, so I'll grab it later.

MDM is out of the question, these are personal devices. With luck the cambium setup gets sorted out and I'll make use of easypass which will allow SSO via Google :)


Yeah you still need to install the root that signs the NPS cert for some Androids, tis annoying. 

Makes sense - am in the same boat. Will easypass also hand certificate distribution? That's the pain point (still)

  • Like 1
Posted

I'd try and get a public/private signed CA for what's it worth how are you dealing with decryption and deploying those certs if you are?

 

Private CA does have it's benefits but you have got to deploy the cert to devices somehow.

 

We use Eduroam where I am and it is easy to download a profile with the correct certs whether they be Public or Private CA

Posted

Decryption is the "easy" part - that's still handled by getting them to install the smoothwall cert via the /getmitm URL as always, it's just this initial bit for authorisation which is adding yet another step.

I'm not aware that Easypass would make it any different regarding inspection, it'd just allow connection similar to NPS with authentication to Google, visible by Smoothwall for monitoring/filtering purposes but still (AFAIK) needs the certificate installing manually.

 

  • Like 1
Posted

We have Aruba Central and push out the HPE onboarding app. This authenticates with their Entra ID (so only staff can get on) and then connects them. Seems the easiest way since all this CA Android stuff came about.

Posted
3 hours ago, Davit2005 said:

I'd try and get a public/private signed CA for what's it worth how are you dealing with decryption and deploying those certs if you are?

 

Private CA does have it's benefits but you have got to deploy the cert to devices somehow.

 

We use Eduroam where I am and it is easy to download a profile with the correct certs whether they be Public or Private CA

We have found that the easiest way for us, is a memory stick, into a A>C adapter which i can then plug into any android phone and install it from within settings.

I can do the local NPS cert and the Smoothwall cert at the same time too so it sppeds up the procces to comparable speeds to the simpler iphone.

Posted

Assuming BYOD, are you installing the root CA or the cert used by the radius server?  Also what about the cert for MITM web traffic inspection?  Does andriod limit the scope for these, or are you required to make personal devices trust all certs for all purposes issued by  your CA?

Posted

BYOD - school devices are easy thanks to MDM. Inspection certs as mentioned are also easy, installed as they normally would be (manually) and indeed users must have traffic inspected. Unless, which is quite possible, I'm misunderstanding and the 2 can be linked?

  • Like 1
Posted
On 15/09/2026 at 10:03, StephenPink said:

We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. 

With CloudPath - what AP's are you using? Are you making visitors use CloudPath with installed certs?

 

We find that visitors from the council, or NHS trusts, often have laptops so locked down you can't install anything on them, let alone a CA cert (quite rightly so)!

Posted
11 minutes ago, psynegy said:

With CloudPath - what AP's are you using? Are you making visitors use CloudPath with installed certs?

 

We find that visitors from the council, or NHS trusts, often have laptops so locked down you can't install anything on them, let alone a CA cert (quite rightly so)!


R670s/T670s. Nah - for Visitors we use the Guest Portal in R1 instead, with voucher codes that are issued by IT/Reception. No SSL inspection on that network - Securly Guest DNS filtering only. Voucher codes so that it can't be used by students.

Cheers

Posted

That's pretty much exactly what we want to do, only our site is so weird and "wonderful" that we simply cannot afford the Ruckus AP's, so we're hoping to get away with Unifi, but there's definitely some (significant) gotchas integrating Unifi with CloudPath...

Posted
25 minutes ago, psynegy said:

That's pretty much exactly what we want to do, only our site is so weird and "wonderful" that we simply cannot afford the Ruckus AP's, so we're hoping to get away with Unifi, but there's definitely some (significant) gotchas integrating Unifi with CloudPath...

PM me and can chat pricing/supplier if it helps... I'm not sure I'd want to try and use CloudPath with another vendors APs. 

I've also been speaking to Unifi about their Endpoint app - as that can do one-click WiFi provisioning, but currently can't deploy certificates... 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...