BatchFile Posted July 4, 2012 Posted July 4, 2012 Just putting my toe in the water coming up with a BYOD system and I want Ruckus to authenticate with AD - that works fine in itself; the annoying bit is that, just like when I log in to the ZD management interface, a certificate error is generated every time with associated scary (for users) warnings. [TABLE=class: posts wide] [TR=class: post hentry] [TD=class: body entry-content]I don’t want to faff about spending £260 on a SSL certificate, but I don’t want anyone logging in to get certificate errors either; ZD's online help says: “If you use HTTPS to connect to the ZoneDirector Web interface, a security warning appears every time you connect to the Web interface.” the “If” in that suggests it should be possible not to use https… where do I switch it off please? [/TD] [/TR] [/TABLE]
glennda Posted July 4, 2012 Posted July 4, 2012 260 quid for a SSL cert? you can get them for free in education! 1
glennda Posted July 4, 2012 Posted July 4, 2012 SSL Certificates SSL Wildcard SSL Free Certificates SSL Server Certificate 256 bits Are you going to be using an Internal Hostname though? or Internal IP to redirect? You would need the hostname to be correct if the cert is to work. Alternatively you can setup a external hostname but connect to the internal address via setting up a zone for it on your DNS server. 2
BatchFile Posted July 4, 2012 Author Posted July 4, 2012 It'd still be much simpler to just turn HTTPS off, so if anyone knows how to do it while I'm figuring the certificate stuff out, please say!
DavidYoung Posted July 4, 2012 Posted July 4, 2012 Alternatively you can setup a external hostname but connect to the internal address via setting up a zone for it on your DNS server. Good idea, I'd wanted to do this for a while, but since we are all .local domains which can't be validated by any CA, we didn't think we could. I've submitted a request for our public domain, and if that works will setup an internal zone. Quick question, the zone should be the entire DNS name right, e.g. ruckus.domainname.org rather than just the domainname.org to allow everything else on that domain to still work? Thanks. David
DavidYoung Posted July 4, 2012 Posted July 4, 2012 It'd still be much simpler to just turn HTTPS off, so if anyone knows how to do it while I'm figuring the certificate stuff out, please say! Much simpler, but you may as well just tell everyone to shout their username and passwords across the playground. The reason why the login page needs to be HTTPS is that the WiFi network you will be connecting to would be unsecure, so you need the security to protect your AD credentials.
BatchFile Posted July 4, 2012 Author Posted July 4, 2012 but you may as well just tell everyone to shout their username and passwords across the playground. They do that anyway! Point taken though...
glennda Posted July 4, 2012 Posted July 4, 2012 Good idea, I'd wanted to do this for a while, but since we are all .local domains which can't be validated by any CA, we didn't think we could. I've submitted a request for our public domain, and if that works will setup an internal zone. Quick question, the zone should be the entire DNS name right, e.g. ruckus.domainname.org rather than just the domainname.org to allow everything else on that domain to still work? Thanks. David Yes just setup the zone as that then when create the record leave the name blank and just put in the IP it will then give it as the name - similar to what you see for DC's in an AD zone.
DavidYoung Posted July 5, 2012 Posted July 5, 2012 Yes just setup the zone as that then when create the record leave the name blank and just put in the IP it will then give it as the name - similar to what you see for DC's in an AD zone. Thanks, I thought so. Thats setup on DNS, got certificate by email, just waiting until downtime to apply it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now