MYK-IT Posted January 19, 2012 Posted January 19, 2012 Hi, Can anyone please advise what type of SSL Certificates I would require (with an indication of supplier/cost) to install suitable SSL Certificates on our Ruckus and SmoothWall appliances? Using the builtin certificates are not a problem for our domain joined computers etc (as they use NTLM Authentication not SSL; and I know that I could push the certifciates out via GPO). The issue is with personal devices connected to the wireless. During the initial authentication process (Ruckus) it is yet another delay/prompt to accept and proceed with the unknown certificate etc. It's not a major issue, but it would be nice to streamline the whole authentication process. Thanks,
White_Fi Posted January 20, 2012 Posted January 20, 2012 You need to generate a CSR from the Ruckus ZD and get it signed by a CA. Thanks Stu
MYK-IT Posted January 31, 2012 Author Posted January 31, 2012 Thanks Stu, Ruckus I've not purchased a SSL Cert before etc, what exact details do i enter, as I get the impression a full WWW URL domain is required to generate etc. The Ruckus is only accessible internally, so would be a internal IP address, or ruckus.{internal domain}.local at most. Any recommendations on type os certificate and/or supplier? Smoothwall Same scenario discussed here: http://www.edugeek.net/forums/smoothwall-direct-support/89345-ssl-certificate-logon.html Many Thanks
Domino Posted January 31, 2012 Posted January 31, 2012 For internal machines, yes a domain signed cert is fine. For external ones what you need is a cert that comes from a common trusted root CA. Personally we use goDaddy, but I know there's a few CAs offering free ssl certs for schools, a quick forum search should scare them up. Don't worry about the domain name being internal, the cert just says that the trusted ca says this site is who they claim to be. 1
MYK-IT Posted January 31, 2012 Author Posted January 31, 2012 Thanks Domino, But I still don't quite grasp exactly what I require.. just been to godaddy website and they have: Standard SSL Single Domain Multiple Domains Single Domains with Unlimited Sub Domains (wildcard) Initially I require a SSL Certificate for both Ruckus and SmoothWall so that users don't have to keep accepting the certificate from each product when logging onto the wireless etc. Long term, a SLL Certificate for future projects like HAP+ and Moodle etc would be required (I assume this would be a different set of certificates?)
Domino Posted January 31, 2012 Posted January 31, 2012 Stuart will tell you definitively, but I don't think the ZD will accept a SAN cert, as it wants it's own from a CSR. So really you'd want two Standard ssl certs, one for the zd and one for the smoothwall. then future projects like HAP+ and Moodle may be able to be under a wildcard cert for external publishing :-)
IrritableTech Posted January 31, 2012 Posted January 31, 2012 We used IPS CA for our ruckus certificate. Free 2 year cert for education... SSL Certificate Authority low-cost, fully-validated 38$ SSL and 276$ Wildcard Certificates In your ZD go to Configure - Certificate. Fill in the info and click Apply. This generates a CR (certificate request) and use this file on the IPS CA website (or as @Domino suggests, there are plenty of others) then they will generate a certificate for you. 1
MYK-IT Posted January 31, 2012 Author Posted January 31, 2012 Update: I've created a SSL Cert with IPS CA, after generating a CR with ZoneDirector. The SSL Cert has been installed and the ZoneDirector rebooted The instructions from IPS CA state about installing additional certificates (from their website) onto our webserver. Not sure of this; as instructions mention IIS etc, and this is for Ruckus Authentication before you get Internet access but i I added their 'bundle pack' into SmoothWall CA Cert section all the same. Tried to access https://{url} and the web browser still state: There is a problem with this website's security certificate. The security certificate presented by this website was not issued by a trusted certificate authority. Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server. Sorry for being a noob.
IrritableTech Posted January 31, 2012 Posted January 31, 2012 Oh yes I remember this now.... I think I installed the certificate into a browser, and the additional ones. Then I exported the whole certificate into one file which could be imported to the ZD... Let me have another look to see if I made any notes. 1
IrritableTech Posted January 31, 2012 Posted January 31, 2012 This page... http://certs.ipsca.com/Support/CSRBarracuda.asp suggests you might just be able to copy and paste the text from the different certificates into one file in the format -----BEGIN CERTIFICATE----- (the signed certificate, several lines of indecipherable text with no spaces) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (the intermediate certificate, several lines of indecipherable text with no spaces) -----END CERTIFICATE----- If that doesn't work for you, I'll do some more digging.
SwedishChef Posted February 23, 2012 Posted February 23, 2012 Did you get this sorted, I'm looking to do the same. Update: I've created a SSL Cert with IPS CA, after generating a CR with ZoneDirector. The SSL Cert has been installed and the ZoneDirector rebooted The instructions from IPS CA state about installing additional certificates (from their website) onto our webserver. Not sure of this; as instructions mention IIS etc, and this is for Ruckus Authentication before you get Internet access but i I added their 'bundle pack' into SmoothWall CA Cert section all the same. Tried to access https://{url} and the web browser still state: There is a problem with this website's security certificate. The security certificate presented by this website was not issued by a trusted certificate authority. Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server. Sorry for being a noob.
MYK-IT Posted February 23, 2012 Author Posted February 23, 2012 (edited) Hi @SwedishChef, Spooky, I was just about to update this thread to say (to @IrritableTech) that I still haven't managed to get this working. It is quite an inconvenience for (BYOD) users to click the various security warning prompts etc whilst attempting to authenticate etc. Not very slick! @IrritableTech, did you manage to dig out your notes? (the one importing various certificates into web browser and exporting a combined one etc?) Many Thanks Edited February 23, 2012 by MYK-IT
IrritableTech Posted February 24, 2012 Posted February 24, 2012 Sorry no. I'm just about to do the same thing on a ruckus controller in one of our primaries. I will get back to you.... perhaps even today...
MYK-IT Posted February 27, 2012 Author Posted February 27, 2012 I am still failing to get my head around this! I'm also still struggling with a SSL Cert for SmoothWall as well! SmoothWall suggest I need a 'website certificate'? I am assuming that many Edugeeker's have successfully configured and installed SSL Certs for Ruckus / SmoothWall and they wouldn't mind spending 5 mins to share their most sought after knowledge Many Thanks.
IrritableTech Posted February 27, 2012 Posted February 27, 2012 Just about to look at this again. It seems the certificate we got issued for our partner primary did not contain the correct information (our fault, our certificate request was wrong), so I'm waiting for the new one to come back. Looking at things again. I don't think you should need to include the ipsCA GLOBAL CA ROOT certificate because that one should be in devices anyway (as long as they are all kept reasonably up-to-date). It might just be that you need to create a cert with the level 1 certificate, and your certificate. I hope to remote into the school this afternoon and attempt to sort out the controller. If I get it working, I will let you know. 1
Ashm Posted February 27, 2012 Posted February 27, 2012 I am still failing to get my head around this! I'm also still struggling with a SSL Cert for SmoothWall as well! SmoothWall suggest I need a 'website certificate'? I am assuming that many Edugeeker's have successfully configured and installed SSL Certs for Ruckus / SmoothWall and they wouldn't mind spending 5 mins to share their most sought after knowledge Many Thanks.I haven't done this with our Smoothwall server yet but I have done this for our Ruckus controller without any issues. I used StartSSL for the SSL Certificate. It was while since I did it but it but it something along the lines of: Re-generate private key length to 2048 bits as StartSSL will not accept anything lower - Zonedirector will reboot at this point Create a new certificate request on Zonedirector and then import that to StartSSL Import Signed Certificate into Zonedirector and then I think it gives you the option to import an intermediate certificate which I did The ZoneDirector will then reboot and hopefully you'll no longer have Certificate warnings So possibly all you need to do re-import the signed certificate and then import the intermediate certificate before rebooting. 1
MYK-IT Posted February 27, 2012 Author Posted February 27, 2012 Thanks Ashm, I may have to restart from scratch then, as I had not changed from the default 1024 bit key. When I get a chance i'll try again, Many Thanks
Ashm Posted February 27, 2012 Posted February 27, 2012 No probs, you may not need to change from 1024 bit. When you originally imported the certificate request to ipsCA it would have come up with an error saying it requires a 2048 bit key length.
IrritableTech Posted March 1, 2012 Posted March 1, 2012 OK, sorry for the late reply MYK-IT We've just tried and tested this on one of our ruckus controllers. We have created a DNS entry for our controller - wifi.example.local which obviously points to the correct I.P. address. We filled in a certificate request on the controller including the Common Name: wifi.example.local and ensuring all other fields were accurate. Using the generated file, we applied for a free 2 year edu certificate from ipsCA, once again taking care with the form. Once we received the certificate email, we copied the full certificate text, into a new text document. We then downloaded the Bundle Certificate from here. Using notepad we copied the full text from the bundle file into our new file in the following format. -----BEGIN CERTIFICATE----- (Your personal signed certificate - wifi.example.local) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (the intermediate certificate - the first section of the Bundle File - First line - MIIF8TCCBNmgAwIBAgIUEAAAAAAAAAAAAAAAAAAAAAAAACMwDQYJKoZIhvcNAQEF) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (the global authority certificate - the second section of the Bundle File - First Line MIIGBzCCBO+gAwIBAgIBADANBgkqhkiG9w0BAQUFADCBsjELMAkGA1UEBhMCRVMx) -----END CERTIFICATE----- We then saved this text file as wifi.example.local.cer and uploaded this to our controller. Hopefully that helps? 1
SwedishChef Posted March 6, 2012 Posted March 6, 2012 OK, I have emailed net-ctrl they are going to confirm with Ruckus if I can imported a cert from gogdady which I had from a CSR generated on my exchange 2010 box.
eduabncs Posted March 6, 2012 Posted March 6, 2012 (edited) Janet offer free SSL Certs to schools via your LEA or RBC. JCS School Extension Edited March 6, 2012 by eduabncs
OverWorked Posted May 24, 2012 Posted May 24, 2012 (edited) I'm just going through the same process: adding certificates to Ruckus ZD and Smoothwall to eliminate certificate errors when users bring in their own devices. I've completed the Ruckus ZD stage, now struggling with Smoothwall. I bought a RapidSSL wildcard certificate from trustico for our external domain. (e.g *.school.sch.uk). You don't need to generate a CSR from a server to do this. From the vendor's website, I downloaded the certificate text file (just change the file extension from .txt to .cer), the private key text file (which I couldn't do anything useful with), and (I think) a .pfx file. I may have generated the .pfx file myself a few months ago after importing the private key and certificate into IIS - I can't remember. I used OpenSSL to extract a private key (.pem) from the .pfx file and used OpenSSL again to remove the password from the private key. This gave me the two files I needed to import into ZD:- the certificate (.cer) the private key (.pem) Import the .cer certificate file first. Because it doesn't match the ZD's private key, ZD will ask for the corresponding private key. Give it the private key, and then give it the certificate again. ZD will reboot and all should be good. This actually took me several attempts to get right, but worked in the end. I recommend getting a wildcard cert if you're going to install on several servers - it's cheaper and less hassle in the long run. Tips : Using openssl to extract private key ( .pem file) from .pfx (Personal Information Exchange) « Cycure That's the Ruckus ZD stage done. Can anyone help me and the OP with putting a certificate into Smoothwall, and getting clients to redirect to the Smoothwall's FQDN instead of the IP addfress, so the address matches the certificate? Thanks. Edited May 24, 2012 by OverWorked
burgemaster Posted November 20, 2014 Posted November 20, 2014 "That's the Ruckus ZD stage done. Can anyone help me and the OP with putting a certificate into Smoothwall, and getting clients to redirect to the Smoothwall's FQDN instead of the IP addfress, so the address matches the certificate?" I know this is an old thread... But thats exactly where I am now!!!! Did you manage to sort this please?
Tallwood_6 Posted November 20, 2014 Posted November 20, 2014 You will need to phone smoothwall currently to get that sorted, they have done just that for us recently. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now