synaesthesia Posted Tuesday at 08:47 Posted Tuesday at 08:47 Starting to have a few more issues with PEAP authentication with newer Android versions and Samsung devices. Up to, I believe, Android 15 it seems quite easy - forgo the CA certificate, provide username and password and remove "anonymous" from the anonymous identity and everything connects hunky dory. Iphones are even less hassle - username, password, trust the smoothwall certificate. end of. However on newer devices and Samsungs, it won't progress without either using a system certificate or installing one, adding yet another step. It's easy to say I'd love to ditch BYOD and I still think it's days are numbered but mobile signal round here is non existent. I'd also love to be able to leverage the options in Cambium but.... we all know why that's probably not worth pursuing at the moment. So for certificates, what exactly are others doing please? I've tried using system certificate and our local domain but that doesn't work, and not a clue what actual certificate to provide for connecting in the first place. Documentation to this effect seems to be all over the shop and my brain hurts
NegativeKillDeath Posted Tuesday at 09:00 Posted Tuesday at 09:00 There was an issue in Pixel phones where they dropped the ability to "do not validate" this appears to have been fixed as now they off a Trust on First Use option which will allow you to use a self signed cert and agree to to when connecting much like iOS does. We are seeing this on recent Pixels and Samsungs. So we make sure that the user has the latest update on their phone and this usually works. 1
StephenPink Posted Tuesday at 09:03 Posted Tuesday at 09:03 We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. The other route is enrol in an MDM... i can share instructions from pre-CloudPath if it helps? Again they were reasonably vague though to try to cover the majority of devices without taking into account the specific variations. Cheers 1
synaesthesia Posted Tuesday at 09:18 Author Posted Tuesday at 09:18 Cheers, no worries - I did see the Trust on First Use option on the Android 16 device I was trying this morning, but it didn't seem to work. I didn't spend much time on it though, so I'll grab it later. MDM is out of the question, these are personal devices. With luck the cambium setup gets sorted out and I'll make use of easypass which will allow SSO via Google
StephenPink Posted Tuesday at 09:34 Posted Tuesday at 09:34 15 minutes ago, synaesthesia said: Cheers, no worries - I did see the Trust on First Use option on the Android 16 device I was trying this morning, but it didn't seem to work. I didn't spend much time on it though, so I'll grab it later. MDM is out of the question, these are personal devices. With luck the cambium setup gets sorted out and I'll make use of easypass which will allow SSO via Google Yeah you still need to install the root that signs the NPS cert for some Androids, tis annoying. Makes sense - am in the same boat. Will easypass also hand certificate distribution? That's the pain point (still) 1
psydii Posted Tuesday at 09:37 Posted Tuesday at 09:37 Its definately worse this september than it has ever been.
Davit2005 Posted Tuesday at 09:38 Posted Tuesday at 09:38 I'd try and get a public/private signed CA for what's it worth how are you dealing with decryption and deploying those certs if you are? Private CA does have it's benefits but you have got to deploy the cert to devices somehow. We use Eduroam where I am and it is easy to download a profile with the correct certs whether they be Public or Private CA
synaesthesia Posted Tuesday at 10:08 Author Posted Tuesday at 10:08 Decryption is the "easy" part - that's still handled by getting them to install the smoothwall cert via the /getmitm URL as always, it's just this initial bit for authorisation which is adding yet another step. I'm not aware that Easypass would make it any different regarding inspection, it'd just allow connection similar to NPS with authentication to Google, visible by Smoothwall for monitoring/filtering purposes but still (AFAIK) needs the certificate installing manually. 1
ITGuyNW Posted Tuesday at 10:33 Posted Tuesday at 10:33 We have Aruba Central and push out the HPE onboarding app. This authenticates with their Entra ID (so only staff can get on) and then connects them. Seems the easiest way since all this CA Android stuff came about.
aydee Posted Tuesday at 13:02 Posted Tuesday at 13:02 3 hours ago, Davit2005 said: I'd try and get a public/private signed CA for what's it worth how are you dealing with decryption and deploying those certs if you are? Private CA does have it's benefits but you have got to deploy the cert to devices somehow. We use Eduroam where I am and it is easy to download a profile with the correct certs whether they be Public or Private CA We have found that the easiest way for us, is a memory stick, into a A>C adapter which i can then plug into any android phone and install it from within settings. I can do the local NPS cert and the Smoothwall cert at the same time too so it sppeds up the procces to comparable speeds to the simpler iphone.
psydii Posted Tuesday at 13:51 Posted Tuesday at 13:51 Assuming BYOD, are you installing the root CA or the cert used by the radius server? Also what about the cert for MITM web traffic inspection? Does andriod limit the scope for these, or are you required to make personal devices trust all certs for all purposes issued by your CA?
synaesthesia Posted Tuesday at 14:03 Author Posted Tuesday at 14:03 BYOD - school devices are easy thanks to MDM. Inspection certs as mentioned are also easy, installed as they normally would be (manually) and indeed users must have traffic inspected. Unless, which is quite possible, I'm misunderstanding and the 2 can be linked? 1
psynegy Posted Wednesday at 13:14 Posted Wednesday at 13:14 On 15/09/2026 at 10:03, StephenPink said: We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. With CloudPath - what AP's are you using? Are you making visitors use CloudPath with installed certs? We find that visitors from the council, or NHS trusts, often have laptops so locked down you can't install anything on them, let alone a CA cert (quite rightly so)!
StephenPink Posted Wednesday at 13:27 Posted Wednesday at 13:27 11 minutes ago, psynegy said: With CloudPath - what AP's are you using? Are you making visitors use CloudPath with installed certs? We find that visitors from the council, or NHS trusts, often have laptops so locked down you can't install anything on them, let alone a CA cert (quite rightly so)! R670s/T670s. Nah - for Visitors we use the Guest Portal in R1 instead, with voucher codes that are issued by IT/Reception. No SSL inspection on that network - Securly Guest DNS filtering only. Voucher codes so that it can't be used by students. Cheers
psynegy Posted Wednesday at 14:30 Posted Wednesday at 14:30 That's pretty much exactly what we want to do, only our site is so weird and "wonderful" that we simply cannot afford the Ruckus AP's, so we're hoping to get away with Unifi, but there's definitely some (significant) gotchas integrating Unifi with CloudPath...
StephenPink Posted Wednesday at 14:59 Posted Wednesday at 14:59 25 minutes ago, psynegy said: That's pretty much exactly what we want to do, only our site is so weird and "wonderful" that we simply cannot afford the Ruckus AP's, so we're hoping to get away with Unifi, but there's definitely some (significant) gotchas integrating Unifi with CloudPath... PM me and can chat pricing/supplier if it helps... I'm not sure I'd want to try and use CloudPath with another vendors APs. I've also been speaking to Unifi about their Endpoint app - as that can do one-click WiFi provisioning, but currently can't deploy certificates...
psynegy Posted Wednesday at 15:42 Posted Wednesday at 15:42 Will do! We're just looking at testing the Endpoint app, but need a gateway device before we can do so.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now