Re: [WIRELESS-LAN] Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Tim Cappalli
This is definitely normal behavior. The only way to get around this would be to configure the client to not verify the server certificate which is a security risk and is not best practice. The idea is that if someone threw up a rogue AP with the same SSID and your users associated to it, they woul

RE: [WIRELESS-LAN] Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Williams, Mr. Michael
It is good to know that what we are seeing is normal behavior and there isn't something mis-configured on our end, but some sort of documentation from wireless manufactures detailing this requirement would be helpful to show users what they are experiencing is just a security requirement and co

RE: [WIRELESS-LAN] Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Lee H Badman
We found Cloudpath ExpressConnect to be wonderful at setting things like approved certs for the client- if you can get them to use it. We have a great mechanism with a "Help" SSID that allows for initial self-config, then self-remediation if you ever find your client not behaving. Works so swee

RE: Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Osborne, Bruce W
Are tour clients trusting the RADIUS server certificate directly? First, we have configured our Windows clients to trust any certificates from our CA, only connect to particular servers (DNS Name), and not prompt to trust new certificates. Our Apple devices (OSX & iOS) are set to trust our CA c

RE: [WIRELESS-LAN] Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Williams, Mr. Michael
Thanks Lee. I am going to take a look at Cloudpath. mike Michael M. Williams Network Systems Analyst Information Technology Services Tarleton State University 201st St. Felix Str. Box T-0220 Stephenville, TX 76402 Tel: (254) 968-1850 Fax: (254) 968-9393 mmwilli...@tarleton.edu

RE: [WIRELESS-LAN] Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Jason Cook
Vote 2 for cloudpath, we have found the software to be extremely helpful in configuring, updating and troubleshooting clients. As already stated this is expected behaviour. Like most IT Security "pains" the best approach is good communication & documentation to set user expectations and educat

RE: [WIRELESS-LAN] Verifying or Validating Server Certificate when using WPA/WPA2 and 8021x WLAN

2013-04-16 Thread Matt Pendleton
Vote 3 on Cloudpath. We have been using this for years. I also agree with what Jason says below on Good Communication and Documentation. We put a lot of effort into our website (https://www.dhnet.ufl.edu) and also we have developed an @Home Checklist (https://www.dhnet.ufl.edu/newresidents/ch