Jump to content

Recommended Posts

Posted

Hi,

 

Can anyone please advise what type of SSL Certificates I would require (with an indication of supplier/cost) to install suitable SSL Certificates on our Ruckus and SmoothWall appliances?

 

Using the builtin certificates are not a problem for our domain joined computers etc (as they use NTLM Authentication not SSL; and I know that I could push the certifciates out via GPO).

The issue is with personal devices connected to the wireless.

 

During the initial authentication process (Ruckus) it is yet another delay/prompt to accept and proceed with the unknown certificate etc.

It's not a major issue, but it would be nice to streamline the whole authentication process.

 

Thanks,

  • 2 weeks later...
Posted

Thanks Stu,

 

Ruckus

I've not purchased a SSL Cert before etc, what exact details do i enter, as I get the impression a full WWW URL domain is required to generate etc.

The Ruckus is only accessible internally, so would be a internal IP address, or ruckus.{internal domain}.local at most.

 

Any recommendations on type os certificate and/or supplier?

 

 

Smoothwall

Same scenario discussed here:

http://www.edugeek.net/forums/smoothwall-direct-support/89345-ssl-certificate-logon.html

 

Many Thanks

Posted

For internal machines, yes a domain signed cert is fine.

 

For external ones what you need is a cert that comes from a common trusted root CA. Personally we use goDaddy, but I know there's a few CAs offering free ssl certs for schools, a quick forum search should scare them up.

 

Don't worry about the domain name being internal, the cert just says that the trusted ca says this site is who they claim to be.

  • Thanks 1
Posted

Thanks Domino,

 

But I still don't quite grasp exactly what I require.. just been to godaddy website and they have:

 


    Standard SSL
    Single Domain
    Multiple Domains
    Single Domains with Unlimited Sub Domains (wildcard)

 

Initially I require a SSL Certificate for both Ruckus and SmoothWall so that users don't have to keep accepting the certificate from each product when logging onto the wireless etc.

 

Long term, a SLL Certificate for future projects like HAP+ and Moodle etc would be required (I assume this would be a different set of certificates?)

Posted

Stuart will tell you definitively, but I don't think the ZD will accept a SAN cert, as it wants it's own from a CSR.

 

So really you'd want two Standard ssl certs, one for the zd and one for the smoothwall. then future projects like HAP+ and Moodle may be able to be under a wildcard cert for external publishing :-)

Posted

We used IPS CA for our ruckus certificate. Free 2 year cert for education... SSL Certificate Authority low-cost, fully-validated 38$ SSL and 276$ Wildcard Certificates

 

In your ZD go to Configure - Certificate. Fill in the info and click Apply. This generates a CR (certificate request) and use this file on the IPS CA website (or as @Domino suggests, there are plenty of others) then they will generate a certificate for you.

  • Thanks 1
Posted

Update:

I've created a SSL Cert with IPS CA, after generating a CR with ZoneDirector.

The SSL Cert has been installed and the ZoneDirector rebooted

 

The instructions from IPS CA state about installing additional certificates (from their website) onto our webserver.

Not sure of this; as instructions mention IIS etc, and this is for Ruckus Authentication before you get Internet access but i I added their 'bundle pack' into SmoothWall CA Cert section all the same.

 

Tried to access https://{url} and the web browser still state:

 

There is a problem with this website's security certificate.

The security certificate presented by this website was not issued by a trusted certificate authority.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.

 

Sorry for being a noob.

Posted

Oh yes I remember this now....

 

I think I installed the certificate into a browser, and the additional ones. Then I exported the whole certificate into one file which could be imported to the ZD...

 

Let me have another look to see if I made any notes.

  • Thanks 1
Posted

This page... http://certs.ipsca.com/Support/CSRBarracuda.asp suggests you might just be able to copy and paste the text from the different certificates into one file in the format

 

-----BEGIN CERTIFICATE-----
(the signed certificate, several lines of indecipherable text with no spaces)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
(the intermediate certificate, several lines of indecipherable text with no spaces)
-----END CERTIFICATE-----

 

If that doesn't work for you, I'll do some more digging.

  • 4 weeks later...
Posted

Did you get this sorted, I'm looking to do the same.

 

Update:

I've created a SSL Cert with IPS CA, after generating a CR with ZoneDirector.

The SSL Cert has been installed and the ZoneDirector rebooted

 

The instructions from IPS CA state about installing additional certificates (from their website) onto our webserver.

Not sure of this; as instructions mention IIS etc, and this is for Ruckus Authentication before you get Internet access but i I added their 'bundle pack' into SmoothWall CA Cert section all the same.

 

Tried to access https://{url} and the web browser still state:

 

There is a problem with this website's security certificate.

The security certificate presented by this website was not issued by a trusted certificate authority.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.

 

Sorry for being a noob.

Posted (edited)

Hi @SwedishChef,

 

Spooky, I was just about to update this thread to say (to @IrritableTech) that I still haven't managed to get this working.

 

It is quite an inconvenience for (BYOD) users to click the various security warning prompts etc whilst attempting to authenticate etc.

 

Not very slick!

 

@IrritableTech, did you manage to dig out your notes? (the one importing various certificates into web browser and exporting a combined one etc?)

 

Many Thanks

Edited by MYK-IT
Posted

I am still failing to get my head around this!

 

I'm also still struggling with a SSL Cert for SmoothWall as well! SmoothWall suggest I need a 'website certificate'?

 

I am assuming that many Edugeeker's have successfully configured and installed SSL Certs for Ruckus / SmoothWall and they wouldn't mind spending 5 mins to share their most sought after knowledge ;)

 

Many Thanks.

Posted

Just about to look at this again. It seems the certificate we got issued for our partner primary did not contain the correct information (our fault, our certificate request was wrong), so I'm waiting for the new one to come back.

 

Looking at things again. I don't think you should need to include the ipsCA GLOBAL CA ROOT certificate because that one should be in devices anyway (as long as they are all kept reasonably up-to-date). It might just be that you need to create a cert with the level 1 certificate, and your certificate.

 

I hope to remote into the school this afternoon and attempt to sort out the controller. If I get it working, I will let you know.

  • Thanks 1
Posted
I am still failing to get my head around this!

 

I'm also still struggling with a SSL Cert for SmoothWall as well! SmoothWall suggest I need a 'website certificate'?

 

I am assuming that many Edugeeker's have successfully configured and installed SSL Certs for Ruckus / SmoothWall and they wouldn't mind spending 5 mins to share their most sought after knowledge ;)

 

Many Thanks.

I haven't done this with our Smoothwall server yet but I have done this for our Ruckus controller without any issues. I used StartSSL for the SSL Certificate.

 

It was while since I did it but it but it something along the lines of:

 

  • Re-generate private key length to 2048 bits as StartSSL will not accept anything lower - Zonedirector will reboot at this point
  • Create a new certificate request on Zonedirector and then import that to StartSSL
  • Import Signed Certificate into Zonedirector and then I think it gives you the option to import an intermediate certificate which I did
  • The ZoneDirector will then reboot and hopefully you'll no longer have Certificate warnings

 

 

So possibly all you need to do re-import the signed certificate and then import the intermediate certificate before rebooting.

  • Thanks 1
Posted

Thanks Ashm,

 

I may have to restart from scratch then, as I had not changed from the default 1024 bit key.

 

When I get a chance i'll try again,

 

Many Thanks

Posted
No probs, you may not need to change from 1024 bit. When you originally imported the certificate request to ipsCA it would have come up with an error saying it requires a 2048 bit key length.
Posted

OK, sorry for the late reply MYK-IT

 

We've just tried and tested this on one of our ruckus controllers.

 

  • We have created a DNS entry for our controller - wifi.example.local which obviously points to the correct I.P. address.
  • We filled in a certificate request on the controller including the Common Name: wifi.example.local and ensuring all other fields were accurate. :D
  • Using the generated file, we applied for a free 2 year edu certificate from ipsCA, once again taking care with the form.
  • Once we received the certificate email, we copied the full certificate text, into a new text document.
  • We then downloaded the Bundle Certificate from here.
  • Using notepad we copied the full text from the bundle file into our new file in the following format.

 

 

-----BEGIN CERTIFICATE-----
(Your personal signed certificate - wifi.example.local)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
(the intermediate certificate - the first section of the Bundle File - First line - MIIF8TCCBNmgAwIBAgIUEAAAAAAAAAAAAAAAAAAAAAAAACMwDQYJKoZIhvcNAQEF)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
(the global authority certificate - the second section of the Bundle File - First Line MIIGBzCCBO+gAwIBAgIBADANBgkqhkiG9w0BAQUFADCBsjELMAkGA1UEBhMCRVMx)
-----END CERTIFICATE-----

 

  • We then saved this text file as wifi.example.local.cer and uploaded this to our controller.

 

 

Hopefully that helps?

  • Thanks 1
  • 2 months later...
Posted (edited)

I'm just going through the same process: adding certificates to Ruckus ZD and Smoothwall to eliminate certificate errors when users bring in their own devices.

 

I've completed the Ruckus ZD stage, now struggling with Smoothwall.

 

I bought a RapidSSL wildcard certificate from trustico for our external domain. (e.g *.school.sch.uk). You don't need to generate a CSR from a server to do this.

 

From the vendor's website, I downloaded the certificate text file (just change the file extension from .txt to .cer), the private key text file (which I couldn't do anything useful with), and (I think) a .pfx file. I may have generated the .pfx file myself a few months ago after importing the private key and certificate into IIS - I can't remember.

 

I used OpenSSL to extract a private key (.pem) from the .pfx file and used OpenSSL again to remove the password from the private key. This gave me the two files I needed to import into ZD:-

 

the certificate (.cer)

the private key (.pem)

 

Import the .cer certificate file first. Because it doesn't match the ZD's private key, ZD will ask for the corresponding private key. Give it the private key, and then give it the certificate again.

 

ZD will reboot and all should be good.

 

This actually took me several attempts to get right, but worked in the end.

 

I recommend getting a wildcard cert if you're going to install on several servers - it's cheaper and less hassle in the long run.

 

Tips : Using openssl to extract private key ( .pem file) from .pfx (Personal Information Exchange) « Cycure

 

That's the Ruckus ZD stage done. Can anyone help me and the OP with putting a certificate into Smoothwall, and getting clients to redirect to the Smoothwall's FQDN instead of the IP addfress, so the address matches the certificate?

 

Thanks.

Edited by OverWorked
  • 2 years later...
Posted

"That's the Ruckus ZD stage done. Can anyone help me and the OP with putting a certificate into Smoothwall, and getting clients to redirect to the Smoothwall's FQDN instead of the IP addfress, so the address matches the certificate?"

 

I know this is an old thread... But thats exactly where I am now!!!!

Did you manage to sort this please?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...