Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Having Trouble with IOS 11 with Captive Portal

This thread has been viewed 5 times
  • 1.  Having Trouble with IOS 11 with Captive Portal

    Posted Nov 07, 2017 02:21 PM

    We are using a publically signed certificate. The iDevices complain about the captive portal. Before the user could tap trust certificate and now that is gone. The Guest is open with a captive portal no WPA2. Any ideas on how to get around this issue without going to a Guest SSID with WPA2, (upper management does not want this). 



  • 2.  RE: Having Trouble with IOS 11 with Captive Portal

    EMPLOYEE
    Posted Nov 07, 2017 02:24 PM
    Is it a SHA2+ cert?
    2048-bit+ key?
    Chained correctly?


  • 3.  RE: Having Trouble with IOS 11 with Captive Portal

    Posted Nov 07, 2017 02:29 PM

    I know it is 2048-bit and is chained correctly. Not sure about the SHA2+



  • 4.  RE: Having Trouble with IOS 11 with Captive Portal

    EMPLOYEE
    Posted Nov 07, 2017 02:32 PM
    Make sure it's SHA2 or greater.


  • 5.  RE: Having Trouble with IOS 11 with Captive Portal

    Posted Nov 07, 2017 02:45 PM

    When I look at the details of the cert:

    Version: V3

    Signature algorithm: sha256RSA

    Signature hash algorithm: sha256

    Issuer GeoTrust DV SSL CA - G3

    Public Key: RSA (2048)

     

    It is valid until June 2018.

     



  • 6.  RE: Having Trouble with IOS 11 with Captive Portal

    Posted Nov 07, 2017 02:47 PM

    It's only happening on iDevices. I have a MAC running High Sierra and it is fine.



  • 7.  RE: Having Trouble with IOS 11 with Captive Portal

    EMPLOYEE
    Posted Nov 07, 2017 02:49 PM
    Is the CNA popping?


  • 8.  RE: Having Trouble with IOS 11 with Captive Portal

    Posted Nov 07, 2017 02:59 PM

    Yes, it is. The user gets the login screen. They are able to see the check box and if they want click on the terms and agreement link to view. Once they click on the link we have it redirect to the hospital's website which is also https. It is saying that not a valid cert when the redirection. Could it be the redirect? But the error is saying the captive portal page cert it does not like not the redirected website.



  • 9.  RE: Having Trouble with IOS 11 with Captive Portal

    EMPLOYEE
    Posted Nov 07, 2017 03:03 PM
    hm. Have not seen that behavior. Best to work with TAC.