Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

How Did You Get EAP-TLS Working?

This thread has been viewed 3 times
  • 1.  How Did You Get EAP-TLS Working?

    Posted Apr 03, 2019 04:28 PM

    Has anybody successfully deployed EAP-TLS for an IOS and or Android environment?  Did you have to install specific public CA certificates on the phones? Were you able to get clients on IOS/Android to use private CA certificates? If not, how did you get the phones to trust the certs?

     

    There's a known issue with Android ignoring certs it doesn't trust and IOS asking the client if it chooses to trust the cert and I'm curious what people here had to do in order to get EAP-TLS to work using iPhones and Androids.  I see no way of sending a cert chain and forcing the phone to trust them via MDM.  

     

    Thanks!



  • 2.  RE: How Did You Get EAP-TLS Working?

    Posted Apr 03, 2019 04:51 PM

    We have successfully deployed EAP-TLS with iPhones. I can tell you it works but unfortunately I can't tell you how we did it as another team manages the phones. I can tell you we use VMware Airwatch to deploy certificates. You might want to look into that and how they do it.



  • 3.  RE: How Did You Get EAP-TLS Working?

    Posted Apr 03, 2019 04:52 PM

    Thanks. Do you get asked whether or not to trust the cert (if you recall) or were you never asked as if it were automatically trusted?  What vendor?



  • 4.  RE: How Did You Get EAP-TLS Working?

    Posted Apr 03, 2019 04:59 PM
    Users do not get asked to trust the certificate. It is pushed down to the phones using profiles. We are using VMware Airwatch to manage and deploy the profiles. It is seamless to the user once the phone is on boarded. I've even had dual WLAN profiles pushed at the same time to migrate users to a new SSID. Almost no users noticed the change.

    Charlie Dean


  • 5.  RE: How Did You Get EAP-TLS Working?

    EMPLOYEE
    Posted Apr 03, 2019 07:46 PM
    Are you asking about managed or unmanaged devices?


  • 6.  RE: How Did You Get EAP-TLS Working?

    Posted Apr 03, 2019 08:26 PM
    Company-provided devices reachable via mdm