Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

This thread has been viewed 1 times
  • 1.  OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 10, 2015 04:14 AM

    Hi,

     

    I have a problem with the iOS and OSX updates.

    After I did these updates and can't connetct to any WPA2 enterprise 802.1x network anymore.

    Controller Model / AP ModelAruba7210 / AP115
    ArubaOS Version 6.4.2.5

    The network authentication in mycase is terminating on the controller ( EAP-PEAP / mschapv2 ) and uses server group which has internal db and radius in it.

    on an other network wich use captive portal L3 authentication the radius/internal db works. 

     

    According to this article : https://developer.apple.com/library/prerelease/mac/releasenotes/General/rn-osx-10.11/ 

    • When negotiating a TLS/SSL connection with Diffie-Hellman key exchange, OS X El Capitan requires a 1024-bit group or larger. OS X El Capitan will not connect to a server that allows negotiation with a 512-bit or smaller group. These connections include:

      • Secure Web (HTTPS)

      • Enterprise Wi-Fi (802.1X)

      • Secure e-mail (IMAP, POP, SMTP)

      • Printing servers (IPPS)

    Is there aleady any exisiting known issue with  this ?

     

    For info I tested this from a factory resetted iPhone and Macbook Pro.

     

    Thank you in advance for your help

     

    Adrien.

     

     

     



  • 2.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    EMPLOYEE
    Posted Jul 10, 2015 08:05 AM
    You should open a TAC case since these operating systems are beta.


    Thanks,
    Tim


  • 3.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 10, 2015 04:39 PM

    Don't know that TAC would/should support a BETA OS.

     

    Ffor what it's worth I'm experiencing the same. Device won't connect to any 802.1X networks.

     

    Capturing_from_Wi-Fi__en0.jpg



  • 4.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    EMPLOYEE
    Posted Jul 10, 2015 04:47 PM

    The factory securelogin and instant.arubanetworks.com certificates are only 1024. Those should never be used in production. You should acquire your own certificate, 2048 or higher.



  • 5.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 20, 2015 01:04 PM

    I am seeing the factory provided certs as 2048...We actually use 2048 bit Thawte certs for our radius.

    Is it safe to assume that Aruba will not field inquiries until IOS9 and OSX10.11 become official releases?

     

    securelogin.png



  • 6.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x
    Best Answer

    EMPLOYEE
    Posted Jul 20, 2015 01:07 PM
    AFAIK, the issue is that the controllers don't support TLS 1.2 for EAP. This
    issue only comes into play when you're using termination.



    Are you able to terminate on your RADIUS server?


  • 7.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 20, 2015 01:15 PM
    No I can't terminate in the server , is it supposed to be unsupported ?


  • 8.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 20, 2015 01:21 PM

    No we terminate directly to the radius servers.  We are seeing similar issues with the clients not able to stay connected to the AP / network.  Not sure I want to put much effort into this at this time, I was just probing on the possible cert challenge as we just renewed the server certs

     

    Thx.



  • 9.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 23, 2015 12:33 PM

    Is there a timeline for TLS 1.2 Support on the Controllers? Surely this won't be a reactive deployment. 



  • 10.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 10, 2015 05:02 PM
    In fact, that's what I'm using for the certificates.
    But If it is 1024 (and it think it is) it should be supported.
    I also reported the problem to Apple


  • 11.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    EMPLOYEE
    Posted Jul 10, 2015 05:06 PM

    You're right. Sorry misread. Thought it said larger than 1028.



  • 12.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Jul 23, 2015 10:00 AM

    iOS 9 public beta 2 is out now.  I am still unable to connect to 802.1x networks.  We are terminating on separate radius servers with a 4096-bit cert.  Never been a problem before, which makes me wonder if it's just a beta bug in iOS 9.



  • 13.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    EMPLOYEE
    Posted Jul 23, 2015 10:02 AM
    Do your radius servers support TLS 1.2?


    Thanks,
    Tim


  • 14.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x
    Best Answer

    Posted Jul 23, 2015 04:37 PM

    I think this took me like 3 hours of fooling around with it.  Mostly because the newest eapol_test from the wpa supplicant has a bug in it apparently that says the authentication failed even though it really succeeded.

     

    But long story short, updating our radius servers and some required perl modules added TLSv1.2 support and our 802.1x network now works with my phone on iOS9.

     

    Thanks for the pointer in the right direction.



  • 15.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Aug 11, 2015 04:49 PM

    +1 for me.

     

    Granted I'm working a few weeks into the future so may be dealing with a different build of 10.11.  That said, I was fighting a MacBook Air over this same issue, uninstalling VPNs, antivirus, etc.; pouring over logs... and then I rebooted.

     

    802.1X now works without issue.  Successive reboots, network interface disable/enables, all continue to auth successfully to our X network.



  • 16.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    Posted Nov 23, 2015 08:17 AM

    Can some body share a step by step procedure to slove this issue.

     

    We lreay have some TAC case open #1788130

     

    Regards

     

    Nimesh



  • 17.  RE: OS X v10.11 - iOS 9 Public Beta Released - Problem 802.1x

    EMPLOYEE
    Posted Nov 23, 2015 08:19 AM

    What RADIUS server are you using?

    Are you using EAP termination?