Re: [Ubnt_users] Https:

2017-02-03 Thread Ridgetop Networks
Maybe an ssl cert would survive reboot with -cs firmware?
https://community.ubnt.com/t5/airOS-Software-Configuration/airOS-5-6-with-Custom-Script-Support/m-p/1624488#U1624488
On Fri, Feb 3, 2017 at 10:18 AM Sam Tetherow  wrote:

> Have you done this post 5.6.4+ firmware?  I just did a quick look through
> the interface and didn't see any place to change the certificate and local
> modifications are wiped on reboot now.
>
> On 02/03/2017 10:02 AM, Jesse DuPont wrote:
>
> To truly do away with the warning, you'd need:
>
> 1) a wildcard cert (say, "*.cpe.pcswin.com")
> 2) that cert installed on every CPE
> 3) a DNS record for every CPE management IP (i.e. "
> 10-2-3-100.cpe.pcswin.com")
> 4) always access the CPE using the DNS record
>
> If you access the CPE via IP directly even with the above cert on it, the
> browser will still throw the cert warning because the FQDN you went to
> (which was just the IP) doesn't match the host name on the cert, which
> would be "*.cpe.pcswin.com".
>
> *Jesse DuPont*
>
> Network Architect
> email: jesse.dup...@celeritycorp.net
> Celerity Networks LLC
>
> Celerity Broadband LLC
> Like us! facebook.com/celeritynetworksllc
>
> Like us! facebook.com/celeritybroadband
> On 2/3/17 8:04 AM, Steve Barnes wrote:
>
> Having several thousand UBNT devices that use HTTPS, is there any way to get 
> around the: Your Connection is not private, then clicking advanced and then 
> Proceed to 10.0.0.1 (unsafe).
>
> Some I have turned the HTTPS off but would like the extra security when doing 
> updates and the like.
>
> I have 6 techs and 10 systems that access all these and wanted to know if 
> there was a work around.
>
> Steve Barnes
> Wireless Operations Manager
> New Lisbon BroadbandNLBC.COMPCSWIN.COM
> 765-584-2288 ext:1101
>
>
>
>
> ___
> Ubnt_users mailing 
> listUbnt_users@wispa.orghttp://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
>
> ___
> Ubnt_users mailing 
> listUbnt_users@wispa.orghttp://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
-- 
Andrew Kaiser
Ridgetop Networks, LLC
417-543-5513
www.ridgetopnetworks.com
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] 5GHz UBNT Issue

2017-02-03 Thread Mitch

get James to chime in

James Craig 

Mitch Koep

218-851-8689 cell


On 02/02/2017 09:11 PM, Mitch wrote:


ok what firmware?

5.5.11 works well for us

5.6.9 and 6.6 did not do so well

Mitch


On 02/02/2017 02:31 PM, Jorge Santiago wrote:

Non AC.


On Thu, Feb 2, 2017 at 3:20 PM Mitch > wrote:


Are these AC?


On 02/02/2017 01:21 PM, Jorge Santiago wrote:

Don't think is virus. Will reboot units later today to check.

Thanks


On Thu, Feb 2, 2017 at 1:35 PM Gino Villarini > wrote:

Virus?

From: > on behalf of Steve
Barnes >

*//*

*/Gino Villarini/*

President
Metro Office Park #18 Suite 304 Guaynabo, Puerto Rico 00968

Reply-To: Ubiquiti Group >
Date: Thursday, February 2, 2017 at 2:30 PM
To: Ubiquiti Group >

Subject: Re: [Ubnt_users] 5GHz UBNT Issue

Did any updates get applied lately.

Check and see if the disable remote management was applied
during update.  Had that happen a few times.  Can you ssh
into them.

Steve Barnes

Wireless Operations Manager

NLBC.com

PCSWIN.com

*From:*ubnt_users-boun...@wispa.org

[mailto:ubnt_users-boun...@wispa.org] *On Behalf Of *Josh
Luthman
*Sent:* Thursday, February 02, 2017 12:47 PM
*To:* Ubiquiti Users Group
*Subject:* Re: [Ubnt_users] 5GHz UBNT Issue

Noise floor has always been fake, I'd ignore it.

Josh Luthman
Office: 937-552-2340 
Direct: 937-552-2343 
1100 Wayne St
Suite 1337
Troy, OH 45373

On Feb 2, 2017 12:45 PM, "Jorge Santiago"
> wrote:

Rebooting won't fix.

On Thu, Feb 2, 2017 at 12:29 PM, Justin Wilson
> wrote:

Reboots fix it?

Justin Wilson
j...@mtin.net 

---
http://www.mtin.net Owner/CEO
xISP Solutions- Consulting – Data Centers - Bandwidth

http://www.midwest-ix.com COO/Chairman
Internet Exchange - Peering - Distributed Fabric


> On Feb 2, 2017, at 12:15 PM, Jorge Santiago
> wrote:
>
> I have two customers, relatively close to our tower, and
cannot log into their CPE. Starting happening a few days ago
customer will complain of slow speeds.
>
>
> Any idea?
>
> Jorge

> <5GHz UBNT.png>___
> Ubnt_users mailing list
> Ubnt_users@wispa.org 
> http://lists.wispa.org/mailman/listinfo/ubnt_users

___
Ubnt_users mailing list
Ubnt_users@wispa.org 
http://lists.wispa.org/mailman/listinfo/ubnt_users


___
Ubnt_users mailing list
Ubnt_users@wispa.org 
http://lists.wispa.org/mailman/listinfo/ubnt_users

___
Ubnt_users mailing list
Ubnt_users@wispa.org 
http://lists.wispa.org/mailman/listinfo/ubnt_users



___
Ubnt_users mailing list
Ubnt_users@wispa.org 
http://lists.wispa.org/mailman/listinfo/ubnt_users


-- 
Mitch Koep


A Better Wireless
218-851-8689 cell

___
Ubnt_users mailing list
Ubnt_users@wispa.org 
http://lists.wispa.org/mailman/listinfo/ubnt_users



___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


--
Mitch Koep

A Better Wireless
218-851-8689 cell


___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


--
Mitch Koep

A Better Wireless
218-851-8689 cell

___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] 5GHz UBNT Issue

2017-02-03 Thread Jorge Santiago
Yeap, same result. Will reboot them tonight to see.

On Fri, Feb 3, 2017 at 7:02 PM Eliezer Sena  wrote:

> Did you tried with another frequency and SSID?
>
> Also try it with 6.0 firmware.
>
> Regards!
> Ing. Eliezer Sena
>
> On Feb 2, 2017 11:46 AM, "Josh Luthman" 
> wrote:
>
> Noise floor has always been fake, I'd ignore it.
>
> Josh Luthman
> Office: 937-552-2340 <(937)%20552-2340>
> Direct: 937-552-2343 <(937)%20552-2343>
> 1100 Wayne St
> Suite 1337
> Troy, OH 45373
>
> On Feb 2, 2017 12:45 PM, "Jorge Santiago"  wrote:
>
> Rebooting won't fix.
>
> On Thu, Feb 2, 2017 at 12:29 PM, Justin Wilson  wrote:
>
> Reboots fix it?
>
> Justin Wilson
> j...@mtin.net
>
> ---
> http://www.mtin.net Owner/CEO
> xISP Solutions- Consulting – Data Centers - Bandwidth
>
> http://www.midwest-ix.com  COO/Chairman
> Internet Exchange - Peering - Distributed Fabric
>
> > On Feb 2, 2017, at 12:15 PM, Jorge Santiago 
> wrote:
> >
> > I have two customers, relatively close to our tower, and cannot log into
> their CPE. Starting happening a few days ago customer will complain of slow
> speeds.
> >
> >
> > Any idea?
> >
> > Jorge
> > <5GHz UBNT.png>___
> > Ubnt_users mailing list
> > Ubnt_users@wispa.org
> > http://lists.wispa.org/mailman/listinfo/ubnt_users
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] 5GHz UBNT Issue

2017-02-03 Thread Jorge Santiago
Thanks.
On Fri, Feb 3, 2017 at 6:41 PM Mitch  wrote:

> get James to chime in
>
> James Craig  
>
> Mitch Koep
>
> 218-851-8689 cell
>
> On 02/02/2017 09:11 PM, Mitch wrote:
>
> ok what firmware?
>
> 5.5.11 works well for us
>
> 5.6.9 and 6.6 did not do so well
>
> Mitch
>
> On 02/02/2017 02:31 PM, Jorge Santiago wrote:
>
> Non AC.
>
>
> On Thu, Feb 2, 2017 at 3:20 PM Mitch  wrote:
>
> Are these AC?
>
> On 02/02/2017 01:21 PM, Jorge Santiago wrote:
>
> Don't think is virus. Will reboot units later today to check.
>
> Thanks
>
>
> On Thu, Feb 2, 2017 at 1:35 PM Gino Villarini  wrote:
>
> Virus?
>
> From:  on behalf of Steve Barnes <
> st...@pcswin.com>
>
>
>
> *Gino Villarini*
> President
> Metro Office Park #18 Suite 304 Guaynabo, Puerto Rico 00968
>
> Reply-To: Ubiquiti Group 
> Date: Thursday, February 2, 2017 at 2:30 PM
> To: Ubiquiti Group 
>
> Subject: Re: [Ubnt_users] 5GHz UBNT Issue
>
> Did any updates get applied lately.
>
>
>
> Check and see if the disable remote management was applied during update.
> Had that happen a few times.  Can you ssh into them.
>
>
>
> Steve Barnes
>
> Wireless Operations Manager
>
> NLBC.com
>
> PCSWIN.com
>
>
>
> *From:* ubnt_users-boun...@wispa.org [mailto:ubnt_users-boun...@wispa.org
> ] *On Behalf Of *Josh Luthman
> *Sent:* Thursday, February 02, 2017 12:47 PM
> *To:* Ubiquiti Users Group
> *Subject:* Re: [Ubnt_users] 5GHz UBNT Issue
>
>
>
> Noise floor has always been fake, I'd ignore it.
>
> Josh Luthman
> Office: 937-552-2340 <%28937%29%20552-2340>
> Direct: 937-552-2343 <%28937%29%20552-2343>
> 1100 Wayne St
> Suite 1337
> Troy, OH 45373
>
>
>
> On Feb 2, 2017 12:45 PM, "Jorge Santiago"  wrote:
>
> Rebooting won't fix.
>
>
>
> On Thu, Feb 2, 2017 at 12:29 PM, Justin Wilson  wrote:
>
> Reboots fix it?
>
> Justin Wilson
> j...@mtin.net
>
> ---
> http://www.mtin.net Owner/CEO
> xISP Solutions- Consulting – Data Centers - Bandwidth
>
> http://www.midwest-ix.com  COO/Chairman
> Internet Exchange - Peering - Distributed Fabric
>
>
> > On Feb 2, 2017, at 12:15 PM, Jorge Santiago 
> wrote:
> >
> > I have two customers, relatively close to our tower, and cannot log into
> their CPE. Starting happening a few days ago customer will complain of slow
> speeds.
> >
> >
> > Any idea?
> >
> > Jorge
>
> > <5GHz UBNT.png>___
> > Ubnt_users mailing list
> > Ubnt_users@wispa.org
> > http://lists.wispa.org/mailman/listinfo/ubnt_users
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
> ___
> Ubnt_users mailing 
> listUbnt_users@wispa.orghttp://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
> --
> Mitch Koep
>
> A Better Wireless
> 218-851-8689 cell
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
> ___
> Ubnt_users mailing 
> listUbnt_users@wispa.orghttp://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
> --
> Mitch Koep
>
> A Better Wireless
> 218-851-8689 cell
>
>
>
> ___
> Ubnt_users mailing 
> listUbnt_users@wispa.orghttp://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
> --
> Mitch Koep
>
> A Better Wireless
> 218-851-8689 cell
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] 5GHz UBNT Issue

2017-02-03 Thread Eliezer Sena
Did you tried with another frequency and SSID?

Also try it with 6.0 firmware.

Regards!
Ing. Eliezer Sena

On Feb 2, 2017 11:46 AM, "Josh Luthman"  wrote:

> Noise floor has always been fake, I'd ignore it.
>
> Josh Luthman
> Office: 937-552-2340 <(937)%20552-2340>
> Direct: 937-552-2343 <(937)%20552-2343>
> 1100 Wayne St
> Suite 1337
> Troy, OH 45373
>
> On Feb 2, 2017 12:45 PM, "Jorge Santiago"  wrote:
>
>> Rebooting won't fix.
>>
>> On Thu, Feb 2, 2017 at 12:29 PM, Justin Wilson  wrote:
>>
>>> Reboots fix it?
>>>
>>> Justin Wilson
>>> j...@mtin.net
>>>
>>> ---
>>> http://www.mtin.net Owner/CEO
>>> xISP Solutions- Consulting – Data Centers - Bandwidth
>>>
>>> http://www.midwest-ix.com  COO/Chairman
>>> Internet Exchange - Peering - Distributed Fabric
>>>
>>> > On Feb 2, 2017, at 12:15 PM, Jorge Santiago 
>>> wrote:
>>> >
>>> > I have two customers, relatively close to our tower, and cannot log
>>> into their CPE. Starting happening a few days ago customer will complain of
>>> slow speeds.
>>> >
>>> >
>>> > Any idea?
>>> >
>>> > Jorge
>>> > <5GHz UBNT.png>___
>>> > Ubnt_users mailing list
>>> > Ubnt_users@wispa.org
>>> > http://lists.wispa.org/mailman/listinfo/ubnt_users
>>>
>>> ___
>>> Ubnt_users mailing list
>>> Ubnt_users@wispa.org
>>> http://lists.wispa.org/mailman/listinfo/ubnt_users
>>>
>>
>>
>> ___
>> Ubnt_users mailing list
>> Ubnt_users@wispa.org
>> http://lists.wispa.org/mailman/listinfo/ubnt_users
>>
>>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] auto disconnect

2017-02-03 Thread Duane Cox
No I am not returning that attribute, that is an excellent suggestion. If 
ubiquiti supports this, this would work.

Thanks

Sent from my iPhone

On Feb 2, 2017, at 4:45 PM, Scott Lambert 
> wrote:

Are you returning a session-timeout attribute from radius? That should tell the 
access server to check with RADIUS again after they have been connected that 
long. I am not sure that I am remembering the attribute name correctly. We set 
it up years ago.

Disclaimer, I don't use radius for the radio link AAA. I just do it for PPPoE, 
DHCP, and hotspot. DHCP would never re-check AAA without a time limit. I don't 
know how Ubiquiti's implemention works.

On February 2, 2017 2:30:52 PM CST, Duane Cox 
> wrote:
Hello.


Is anyone running a script or batch process to auto disconnect your ubiquiti 
subscribers for non-pay?
I assume another a better way to do this would be through a payment portal; we 
aren't setup for that yet.


We authenticate the CPE via RADIUS at the AP, but if the user fails to pay, 
they will not fail the RADIUS authentication unless the CPE becomes 
dis-associated in some way.


Is there an authentication refresh interval or encryption key 
expiration/renewal feature that would force a refresh of the RADIUS attributes 
and then kick the CPE for failure?


Generally, I would use SNMP to write to the CPE to either reboot it or down an 
interface.  My understanding is that UBNT doesn't support SNMP write, or am I 
incorrect?


Thanks,
Duane Cox
Cox Wireless

--
Sent from my Android device with K-9 Mail. Please excuse my brevity.
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] Https:

2017-02-03 Thread Jay Weekley
I've read about ways to disable those notifications on individual 
computers but haven't tried it yet.

ty...@wigi.us wrote:
> Wish I knew of one curious if anyone does.  :-)
>
> - Original Message -
> Subject: [Ubnt_users] Https:
> From: "Steve Barnes" 
> Date: 2/3/17 10:04 am
> To: "'Ubiquiti Users Group (ubnt_users@wispa.org)'"
> 
>
> Having several thousand UBNT devices that use HTTPS, is there any
> way to get around the: Your Connection is not private, then
> clicking advanced and then Proceed to 10.0.0.1 (unsafe).
>
> Some I have turned the HTTPS off but would like the extra security
> when doing updates and the like.
>
> I have 6 techs and 10 systems that access all these and wanted to
> know if there was a work around.
>
> Steve Barnes
> Wireless Operations Manager
> New Lisbon Broadband
> NLBC.COM
> PCSWIN.COM
> 765-584-2288 ext:1101
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
> No virus found in this message.
> Checked by AVG - www.avg.com 
> Version: 2016.0.7998 / Virus Database: 4756/13884 - Release Date: 02/02/17
>

___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] Https:

2017-02-03 Thread Sam Morris
Can you not somehow use certificates to get around that nag?

On 2/3/2017 9:30 AM, ty...@wigi.us wrote:
> Wish I knew of one curious if anyone does.  :-)
>
> - Original Message -
> Subject: [Ubnt_users] Https:
> From: "Steve Barnes" 
> Date: 2/3/17 10:04 am
> To: "'Ubiquiti Users Group (ubnt_users@wispa.org)'"
> 
>
> Having several thousand UBNT devices that use HTTPS, is there any
> way to get around the: Your Connection is not private, then clicking
> advanced and then Proceed to 10.0.0.1 (unsafe).
>
> Some I have turned the HTTPS off but would like the extra security
> when doing updates and the like.
>
> I have 6 techs and 10 systems that access all these and wanted to
> know if there was a work around.
>
> Steve Barnes
> Wireless Operations Manager
> New Lisbon Broadband
> NLBC.COM
> PCSWIN.COM
> 765-584-2288 ext:1101
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>
>
>
> ___
> Ubnt_users mailing list
> Ubnt_users@wispa.org
> http://lists.wispa.org/mailman/listinfo/ubnt_users
>

___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] Https:

2017-02-03 Thread tyson
 
Wish I knew of one curious if anyone does.  :-)
- Original Message - Subject: [Ubnt_users] Https:
From: "Steve Barnes" 
Date: 2/3/17 10:04 am
To: "'Ubiquiti Users Group (ubnt_users@wispa.org)'" 

Having several thousand UBNT devices that use HTTPS, is there any way to get 
around the: Your Connection is not private, then clicking advanced and then 
Proceed to 10.0.0.1 (unsafe).
 
 Some I have turned the HTTPS off but would like the extra security when doing 
updates and the like.
 
 I have 6 techs and 10 systems that access all these and wanted to know if 
there was a work around.
 
 Steve Barnes
 Wireless Operations Manager
 New Lisbon Broadband
 NLBC.COM
 PCSWIN.COM
 765-584-2288 ext:1101
 
 ___
 Ubnt_users mailing list
 Ubnt_users@wispa.org
 http://lists.wispa.org/mailman/listinfo/ubnt_users
___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


[Ubnt_users] Https:

2017-02-03 Thread Steve Barnes
Having several thousand UBNT devices that use HTTPS, is there any way to get 
around the: Your Connection is not private, then clicking advanced and then 
Proceed to 10.0.0.1 (unsafe).

Some I have turned the HTTPS off but would like the extra security when doing 
updates and the like.

I have 6 techs and 10 systems that access all these and wanted to know if there 
was a work around.

Steve Barnes
Wireless Operations Manager
New Lisbon Broadband
NLBC.COM
PCSWIN.COM
765-584-2288 ext:1101

<>___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] Https:

2017-02-03 Thread Sam Tetherow
I think you are stuck with browser hacks.  The problem is that the 
certificate needs to contain the hostname for the individual site which 
is then used to check with DNS for that hostname to see if it matches 
the IP.



You might have been able to circumvent it by using a wildcard 
certificate and internal dns to resolve something like 
192-168-1-1.pcswin.com, but then you would have to access the radios 
with a longer name rather than by IP.  But with the 5.6.4+ firmware I'm 
not even sure if you can replace the certificate on the radio and have 
it survive a reboot.



On 02/03/2017 09:04 AM, Steve Barnes wrote:

Having several thousand UBNT devices that use HTTPS, is there any way to get 
around the: Your Connection is not private, then clicking advanced and then 
Proceed to 10.0.0.1 (unsafe).

Some I have turned the HTTPS off but would like the extra security when doing 
updates and the like.

I have 6 techs and 10 systems that access all these and wanted to know if there 
was a work around.

Steve Barnes
Wireless Operations Manager
New Lisbon Broadband
NLBC.COM
PCSWIN.COM
765-584-2288 ext:1101



___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


Re: [Ubnt_users] Https:

2017-02-03 Thread Sam Tetherow
Have you done this post 5.6.4+ firmware?  I just did a quick look 
through the interface and didn't see any place to change the certificate 
and local modifications are wiped on reboot now.



On 02/03/2017 10:02 AM, Jesse DuPont wrote:

To truly do away with the warning, you'd need:

1) a wildcard cert (say, "*.cpe.pcswin.com")
2) that cert installed on every CPE
3) a DNS record for every CPE management IP (i.e. 
"10-2-3-100.cpe.pcswin.com")

4) always access the CPE using the DNS record

If you access the CPE via IP directly even with the above cert on it, 
the browser will still throw the cert warning because the FQDN you 
went to (which was just the IP) doesn't match the host name on the 
cert, which would be "*.cpe.pcswin.com".


*_Jesse DuPont_*

Network Architect
email: jesse.dup...@celeritycorp.net
Celerity Networks LLC

Celerity Broadband LLC
Like us! facebook.com/celeritynetworksllc

Like us! facebook.com/celeritybroadband

On 2/3/17 8:04 AM, Steve Barnes wrote:

Having several thousand UBNT devices that use HTTPS, is there any way to get 
around the: Your Connection is not private, then clicking advanced and then 
Proceed to 10.0.0.1 (unsafe).

Some I have turned the HTTPS off but would like the extra security when doing 
updates and the like.

I have 6 techs and 10 systems that access all these and wanted to know if there 
was a work around.

Steve Barnes
Wireless Operations Manager
New Lisbon Broadband
NLBC.COM
PCSWIN.COM
765-584-2288 ext:1101



___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users




___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users


___
Ubnt_users mailing list
Ubnt_users@wispa.org
http://lists.wispa.org/mailman/listinfo/ubnt_users