Hey Daniel,

I've dusted off the test server this morning and ran through some
scenarios. Both Jellybean (4.4.2) and Lollipop (5.X) devices are onboarding
correctly. Ive deployed PF as a self-signed CA, it also generates the end
device cert. The only certificate warning I receive is when I get
redirected to the portal. This is expected and is the only time you would
require a signed trusted certificate.
The process I followed is:
Create a test user
>From a device, connect to the guest wireless network
Browse to a website with the device
Redirect and login to the PF portal with the assigned credentials
PF asks me to note down the cert password and to provide an email address
I then get the link to push the settings
Instead of clicking it, I open the preinstalled packetfence agent
I click the configure button
It asks for the certificate password I noted earlier
It asks me name the cert that is being installed and what it is use is
(credential use: WiFi)
It says the CA cert is included.
The cert successfully, followed by the secure network profile. This
automatically happens after setting the cert name.
I automatically change to the secure network.

I haven't used PF 6 yet but I've been setting up my lab at home for the
auld CCIE studies so I will setup PF 6 on this over the next few days and
test the same scenario.

The key point is you don't need a trusted signed cert for the onboarding
process.. The CA cert will be installed as part of the onboarding process.
Does the onboarding work for you with a windows laptop?

Thanks,

Jonathan




On 27 April 2016 at 07:26, Hack, Daniel (DPIPWE) <
[email protected]> wrote:

> Hi Jonathan,
>
>
>
> Thanks for getting back to me.
>
> Sounds like we might be having a similar issue as you’ve mentioned in your
> original setup.
>
> We did setup PF as a clean install though, so I don’t think we’re
> inheriting any previous provisioning attempts.
>
> With each new release, we find it cleaner to start from scratch with a new
> VM.
>
> Without diving into debug apps on the Android, it ‘appears’ as though
> we’re having a certificate trust issue.
>
> Unfortunately we’re not seeing any prompt to accept it and have it trusted.
>
> I have a feeling that purchasing a certificate might get around it, but
> can’t see a way of integrating that approach with the PF PKI.
>
> I would prefer to use the PF PKI and EAP if we could get the Android to
> trust.
>
> We could forego the google store passthrough, as you’ve done, if we could
> get this part to work.
>
> Our only available testing device is a Samsung Galaxy S tablet running
> Android 4.4.2.
>
> Would be really helpful to hear how you go with testing a Lollipop Android?
>
>
>
> Thanks again for your help.
>
> Cheers,
>
> Dan
>
>
>
>
>
> *From:* Jonathan Mahady [mailto:[email protected]]
> *Sent:* Tuesday, 26 April 2016 9:44 AM
>
> *To:* [email protected]
> *Subject:* Re: [PacketFence-users] SSL server certificate for use with
> Android
>
>
>
> Hey Daniel,
>
> I just wanted to give you an update. I completely forgot the day off for
> anzac day yesterday so I was unable to fire up the lab. However I did find
> my testing notes. As i mentioned in my previous email. I couldn't get the
> android google store (australia) bypass to work. I preinstalled the app and
> when PF asked me to install the app I then clicked the installed app and it
> asked me for the cert password and it then proceeded to install the
> settings. I did get a cert warning as the CA cert wasn't trusted but I just
> accepted this on the test phone and it was installed in the phones trusted
> certs with the device cert. The wireless settings were also pushed
> successfully.
>
> I did have a issue with my originally setup, specifically around the
> provisioning were it just wouldn't work at all (like the issue your having)
> and to resolve it I had to do a fresh install of packetfence and manually
> restore the settings.
>
> For onboarding, you will just a private self-signed CA cert for the
> onboarding process, this must be accepted by the user as part of the
> onboarding process and it typical for NAC solutions to use self-signed
> certs for EAP authentications.
>
> I won't be back in the office until Thursday but I'm curious to see if I
> have any issues with a lollipop android device as I only tested with
> Jellybean. I'll get back to you with my progress.
>
> Cheers,
>
> Jonathan
>
>
>
>
>
> On 20 April 2016 at 10:52, Hack, Daniel (DPIPWE) <
> [email protected]> wrote:
>
> Thanks Jonathan, that would be great!
>
> I’ve tried your approach just now…
>
> Connect to the open SSID, authenticate to the portal, launch the agent and
> click configure.
>
> I get prompted for the certificate password (PF PKI client certificate for
> EAP), which is promising, but the agent gives ‘error: cannot create network’
>
> I can only guess that’s due to the cert being untrusted on the Android’s
> trusted root store.
>
> If you get a chance to have a look at your test lab next week, that would
> be great!
>
> Thanks,
>
> Dan
>
>
>
> *From:* Jonathan Mahady [mailto:[email protected]]
> *Sent:* Wednesday, 20 April 2016 11:18 AM
>
>
> *To:* [email protected]
> *Subject:* Re: [PacketFence-users] SSL server certificate for use with
> Android
>
>
>
> Hey Daniel,
>
> From memory I had to click the application once it got to that page. The
> profile and certs were then pushed (you need to accept the cert error).
> With any of the NAC solutions I've worked with the radius cert has always
> been apart of clients domain CA and PKI infrastructure. The CA cert is then
> pushed to the client which the user has to accept along with their newly
> created device cert. I have a test lab in the office, let me fire up a
> packetfence instance and test it again. I won't be in the office until
> Monday, I'll drop you an update then.
>
>
>
>
>
>
>
> On 20 April 2016 at 08:12, Hack, Daniel (DPIPWE) <
> [email protected]> wrote:
>
> Hi Jonathan,
>
>
>
> Thanks for your reply.
>
> We’ve had the same problem with getting the app downloaded to the Android
> via passthrough.
>
> If you have an Android with the app already installed, how are you getting
> the wireless profile from the provisioner onto the device?
>
> We’re seeing that even with the agent installed, when you ‘Click here to
> install your generated wireless profile’, the browser still tries to go to
> the Google app store URL?
>
> Did you edit the template to pull the profile from the PF server somehow?
>
>
>
> Thanks,
>
> Dan
>
>
>
>
>
> *From:* Jonathan Mahady [mailto:[email protected]]
> *Sent:* Wednesday, 20 April 2016 9:04 AM
> *To:* [email protected]
> *Subject:* Re: [PacketFence-users] SSL server certificate for use with
> Android
>
>
>
> Hi Daniel,
>
> When I was testing android device I had no problem with any third party
> certs I used. The only issue I had was around allow access to the google
> play store so that users could download the app.I couldn't get the
> whitelisting for google australia to work. In the end I just asked users to
> install the packetfence app before onboarding.
>
> Cheers,
>
> Jonathan
>
>
>
> On 19 April 2016 at 18:57, Louis Munro <[email protected]> wrote:
>
>
>
> In a last ditch effort to try to get Android devices working with
> PacketFence,
> we are looking at purchasing a server certificate from a trusted CA, that
> is included in Android’s trusted root store.
>
>
>
> Has anybody been down this path?
>
> Any recommendations for certificate providers?
>
>
>
> Hi Daniel,
>
> Not sure if I missed your earlier messages to the list about this, but
> Android usually works well on PacketFence.
> Can you tell us a bit more about what exactly is not working and what
> leads you to believe it's related to the certificates?
>
> As for recommendations, a certificate is a certificate.
> If it's been issued by a CA trusted by the device it should just work.
>
> I have experience with InCommon, but that is not an exclusive endorsement.
>
> Regards,
>
> --
>
> Louis Munro
> [email protected]  ::  www.inverse.ca
> +1.514.447.4918 x125  :: +1 (866) 353-6153 x125
> Inverse inc. :: Leaders behind SOGo (www.sogo.nu) and PacketFence (
> www.packetfence.org)
>
>
>
> ------------------------------------------------------------------------------
> Find and fix application performance issues faster with Applications
> Manager
> Applications Manager provides deep performance insights into multiple
> tiers of
> your business applications. It resolves application problems quickly and
> reduces your MTTR. Get your free trial!
> https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
>
>
> ------------------------------
>
>
> CONFIDENTIALITY NOTICE AND DISCLAIMER
> The information in this transmission may be confidential and/or protected
> by legal professional privilege, and is intended only for the person or
> persons to whom it is addressed. If you are not such a person, you are
> warned that any disclosure, copying or dissemination of the information is
> unauthorised. If you have received the transmission in error, please
> immediately contact this office by telephone, fax or email, to inform us of
> the error and to enable arrangements to be made for the destruction of the
> transmission, or its return at our cost. No liability is accepted for any
> unauthorised use of the information contained in this transmission.
>
>
>
> ------------------------------------------------------------------------------
> Find and fix application performance issues faster with Applications
> Manager
> Applications Manager provides deep performance insights into multiple
> tiers of
> your business applications. It resolves application problems quickly and
> reduces your MTTR. Get your free trial!
> https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
>
>
> ------------------------------
>
>
> CONFIDENTIALITY NOTICE AND DISCLAIMER
> The information in this transmission may be confidential and/or protected
> by legal professional privilege, and is intended only for the person or
> persons to whom it is addressed. If you are not such a person, you are
> warned that any disclosure, copying or dissemination of the information is
> unauthorised. If you have received the transmission in error, please
> immediately contact this office by telephone, fax or email, to inform us of
> the error and to enable arrangements to be made for the destruction of the
> transmission, or its return at our cost. No liability is accepted for any
> unauthorised use of the information contained in this transmission.
>
>
>
> ------------------------------------------------------------------------------
> Find and fix application performance issues faster with Applications
> Manager
> Applications Manager provides deep performance insights into multiple
> tiers of
> your business applications. It resolves application problems quickly and
> reduces your MTTR. Get your free trial!
> https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
>
> ------------------------------
>
> CONFIDENTIALITY NOTICE AND DISCLAIMER
> The information in this transmission may be confidential and/or protected
> by legal professional privilege, and is intended only for the person or
> persons to whom it is addressed. If you are not such a person, you are
> warned that any disclosure, copying or dissemination of the information is
> unauthorised. If you have received the transmission in error, please
> immediately contact this office by telephone, fax or email, to inform us of
> the error and to enable arrangements to be made for the destruction of the
> transmission, or its return at our cost. No liability is accepted for any
> unauthorised use of the information contained in this transmission.
>
>
> ------------------------------------------------------------------------------
> Find and fix application performance issues faster with Applications
> Manager
> Applications Manager provides deep performance insights into multiple
> tiers of
> your business applications. It resolves application problems quickly and
> reduces your MTTR. Get your free trial!
> https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
>
------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to