Tim, Thank you. This was extremely helpful.
__________________________________ __________________________________ Fishel Erps, Sr. Network & Infrastructure Engineer School of Visual Arts <x-apple-data-detectors://0/1>136 W 21st St., 8th Floor <x-apple-data-detectors://0/1> <x-apple-data-detectors://0/1>New York, NY, 10011 <x-apple-data-detectors://0/1> LL: 212-592-2416 E: [email protected] _______________________________ Please excuse any typographical errors as this e-mail has been sent from my mobile device _______________________________ On Sep 22, 2020, at 15:13, Tim Cappalli < [email protected]> wrote: Fishel - as an aside, if the configuration guidance to users has been to ignore the EAP server identity or configure their devices to not validate it and the credential used for Wi-Fi is their primary password, I highly recommend you issue an organization-wide password reset as all of those credentials may have been compromised. ------------------------------ *From:* The EDUCAUSE Wireless Issues Community Group Listserv < [email protected]> on behalf of Felix Windt < [email protected]> *Sent:* Tuesday, September 22, 2020 15:10 *To:* [email protected] <[email protected] > *Subject:* Re: [WIRELESS-LAN] Android 11 and WPA-Enterprise https://www.eduroam.org/configuration-assistant-tool-cat/ thx, felix *From: *The EDUCAUSE Wireless Issues Community Group Listserv < [email protected]> on behalf of Patrick Mauretti < [email protected]> *Reply-To: *The EDUCAUSE Wireless Issues Community Group Listserv < [email protected]> *Date: *Tuesday, September 22, 2020 at 3:02 PM *To: *"[email protected]" < [email protected]> *Subject: *Re: [WIRELESS-LAN] Android 11 and WPA-Enterprise Okay I’ll bite. What’s the CAT tool you mentioned? Link? -Patrick *From:* The EDUCAUSE Wireless Issues Community Group Listserv < [email protected]> *On Behalf Of *Floyd, Brad *Sent:* Tuesday, September 22, 2020 3:00 PM *To:* [email protected] *Subject:* Re: [WIRELESS-LAN] Android 11 and WPA-Enterprise *CAUTION:* This email originated from outside of Massasoit. Do not click links or open attachments unless you recognize the sender and know the content is safe. Fishel, We have run into this on some versions of Android OS and the solution that works for us is to import our CA’s root certificate into the device. Once we import the root certificate and select it during the profile setup, the connection is established. Thanks, Brad *From:* The EDUCAUSE Wireless Issues Community Group Listserv [ mailto:[email protected] <[email protected]>] *On Behalf Of *Fishel Erps *Sent:* Tuesday, September 22, 2020 12:10 PM *To:* [email protected] *Subject:* Re: [WIRELESS-LAN] Android 11 and WPA-Enterprise Tim, We use: EAP Method = PEAP Phase 2 = MSCHAPv2 CA Certificate = Unspecified Identity = [username] Password = [password] The credentials trigger the return of a filter-ID from the RADIUS server to the controller, which the controller then uses to put the user into a VLAN. Some android devices that are running version 11 no-longer have an option of “unspecified” under CA Certificate, and none of the other choices seem to work. __________________________________ __________________________________ Fishel Erps, Sr. Network & Infrastructure Engineer School of Visual Arts 136 W 21st St., 8th Floor New York, NY, 10011 LL: 212-592-241 <212-592-2416>6 E: [email protected] _______________________________ Please excuse any typographical errors as this e-mail has been sent from my mobile device _______________________________ On Sep 22, 2020, at 12:04, Tim Cappalli < [email protected]> wrote: Can you please provide some basic details? - What exactly is "broken"? - Which EAP method? - Which credential type? - How is/was the supplicant provisioned? - Are only new devices affected or just upgraded devices? ------------------------------ *From:* The EDUCAUSE Wireless Issues Community Group Listserv < [email protected]> on behalf of Fishel Erps < [email protected]> *Sent:* Tuesday, September 22, 2020 12:02 *To:* [email protected] <[email protected] > *Subject:* [WIRELESS-LAN] Android 11 and WPA-Enterprise Hi, v11 seems to have broken credential authentication for RADIUS and WPA2-Enterprise/802.1x. Has anyone found a workaround? __________________________________ __________________________________ Fishel Erps, Sr. Network & Infrastructure Engineer School of Visual Arts 136 W 21st St., 8th Floor New York, NY, 10011 LL: 212-592-2416 C: 347-539-6380 E: [email protected] _______________________________ Please excuse any typographical errors as this e-mail has been sent from my mobile device _______________________________ ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Ctim.cappalli%40MICROSOFT.COM%7Cd8595b131382472a2b5e08d85f2b2349%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637363986174081484&sdata=itVkhcskfJUWCJDsPmVYfOP4hjAMwda6zeAlqf9n2%2Fg%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinkprotect.cudasvc.com%2Furl%3Fa%3Dhttps%253a%252f%252fwww.educause.edu%252fcommunity%26c%3DE%2C1%2CDVsJezVNbC-Bu8iK8EC73RXBiDNNtsRQO_ckowELWILmF1MKA2YEacySjZV14zIJtaDjL3Ywap4VU8NU2hf3vxjlpofH8N5smhn0lhtq6HcDTn6KCCL3sPo%2C%26typo%3D1&data=02%7C01%7Ctim.cappalli%40MICROSOFT.COM%7Cd8595b131382472a2b5e08d85f2b2349%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637363986174086480&sdata=k8L%2BeESvJhsaJViqNnuh56JoLziRXUhMP6kI6RXqINs%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinkprotect.cudasvc.com%2Furl%3Fa%3Dhttps%253a%252f%252fwww.educause.edu%252fcommunity%26c%3DE%2C1%2Cyq4hTl04_UVqyGPLuFZBA9iz9FtFbJ1-QanH8aKwoCztYWvrMqalTfzCmR-f7eZsCL1s-2Sf64q5qoPey5hYfdC9VWj51FkYqfrFRy7et_d5ekSy%26typo%3D1&data=02%7C01%7Ctim.cappalli%40MICROSOFT.COM%7Cd8595b131382472a2b5e08d85f2b2349%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637363986174091474&sdata=eApFIne%2BL2Vas1onSeEC6ArvVQkDk3f2ZoiTyrNToJM%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinkprotect.cudasvc.com%2Furl%3Fa%3Dhttps%253a%252f%252fwww.educause.edu%252fcommunity%26c%3DE%2C1%2CTKuBUMvg2gtAKlCop7fY9CRWoVqHKa4YwHP6KNOEH0i4Vus-Rj1Koqp3UWo0M1btxtmU05pzlE51nC-lGECo8vXsNJSB5zQiS5vzZw_LQixFGQ%2C%2C%26typo%3D1&data=02%7C01%7Ctim.cappalli%40MICROSOFT.COM%7Cd8595b131382472a2b5e08d85f2b2349%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637363986174101462&sdata=JkS2DbI14d3QRDL14G0nVqDWP4b0KcUNl4qcs1nmJYo%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Ctim.cappalli%40MICROSOFT.COM%7Cd8595b131382472a2b5e08d85f2b2349%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637363986174106443&sdata=9TFpqOVLnEi9AyMR9pFUFztC%2F5Sd16ek8%2BGuK%2BJbCPY%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Ctim.cappalli%40MICROSOFT.COM%7Cd8595b131382472a2b5e08d85f2b2349%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637363986174111431&sdata=Td3AT2Lgh5EzwSegVYxYSftGyWk3rIvkYKPSrb1jz18%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
