Wireless Access

Reply
Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

AD authentication require certificate - apple device not works

Hi guys,

I have a little problem with AD authentication.
I have a controller and some APs, i have two SSID, one for employees, and one for guests.

I have configured my controller in way that for the employee access, it require an AD user.


To do this,i have configured a IAS Server that is a radius server that contacts my Active directory.

But this not works properly , for some reason, when i connect to employee SSID, the controller requires a CERTIFICATE.

If i click "continue" it works.. but i don't want that it requires something other by AD user.

 

another issue is that if i try to link an apple device it not works.

 

can you help me please?
thanks in advance
Best regards

Andrea
Guru Elite
Posts: 8,335
Registered: ‎09-08-2010

Re: AD authentication require certificate - apple device not works

[ Edited ]

That is a normal part of the PEAP process. The server is saying "Hey, do you trust me to take your credentials?"

 

The only way around this would be to either manually configure the clients to trust the CA, or use a tool like ClearPass QuickConnect to configure the trust settings automagically.


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Aruba
Posts: 1,368
Registered: ‎12-12-2011

Re: AD authentication require certificate - apple device not works

The issue is that the Apple devices don't trust the server certificate.  Check your AAA profile.  Is EAP Termination enabled/checked off? If so, then you are using the controller certificate.  If not, then you are using the certificate on IAS.  

 

Either way, you need to have that cert signed by a trusted public CA - Verisign, Entrust, GoDaddy, etc... 

 

That is the only way to bypass the continue button on Apple.  However, keep in mind that this will only happen once.  Once you trust as the user, you shouldn't have to hit that step again.

Seth R. Fiermonti
Consulting Systems Engineer - ACCX, ACDX, ACMX
Email: seth@hpe.com
-----
If you found my post helpful, please give kudos
Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

Re: AD authentication require certificate - apple device not works

Hi,
Like you can view in image that i have attached.
the certificate is presented by a trusted public CA GeoTrust Global CA.

so, even if the certificate is pubblic, i have this issue.

any idea?

Andrea
Search Airheads
Showing results for 
Search instead for 
Did you mean: