Certificates and Unified Wireless

Hi people,

I am currently deploy a unified wireless network and that you have run into a bit of a problem with certificates - unfortunately they aren't my specialist subject!

We will deploy two wireless networks (comments and Corp comments) will be tunnel to a dedicated WLC and Corp. will REAP: break-out to the local network with authentication PEAP against AD (via Cisco ACS).  We will have 7 WLCs (including anchor comments) that will be managed by the WCS.

The problems I face with certificates, it's that I don't know how and where to place them - it is my understanding:

cert 1 x GBA for AD authentication

1 cert of x on the WCS for the connection of the Web page (to stop the alert cert)

1 x mobility anchor cert (to stop the alert cert for guest access)

I guess that since the other WLC will not be recorded on they do not need a cert that everything will be done through WCS and comments "web-auth" page is served rather than the WLC mobility anchor central 6?

Ideally, we don't want warnings cert to appear as that will generate the number of calls from users, only for us to tell them "just click ok and it'll be fine"

I'm trying to know if we have a certification authority internal, can I use to get certificates for the WCS and ACS that will sort the internal clients, then an 'external' for guests cert.

Worst case, we would need to get the 'external' certs for all three, but I'm confused as to how it works as our internal domain is a 'private' name [example.private] rather than a public .com [example.com]

Any guideance you can give to would be great!

Thanks in advance

KeV

Well, if you have a domestic certification authority and it is in the store root approved devices, you won't this certificate error message.  If you go with a 3rd party certificate, then you can go the road that you have:

cert 1 x GBA for AD authentication

1 cert of x on the WCS for the connection of the Web page (to stop the alert cert)

1 x mobility anchor cert (to stop the alert cert for guest access)

Or if you want less of certificates, you can do this:

1 cert x the GBA for AD authentication and mobility anchor (to stop the alert cert for guest access)

1 cert of x on the WCS for the connection of the Web page (to stop the alert cert)

Just use a name CN which is general... like wifi.private or something like that.

Scott

Tags: Cisco Wireless

Similar Questions

  • iPhone and Secure Wireless - PEAP

    We recently deployed a new wireless infrastructure using 4404 WLC and 1131 Access Points.  We have 2 WLAN, a secure using RADIUS (Microsoft IAS on Win2K3) and PEAP.  The other access to public comments using the authorization of web WLC.

    We discovered that iPhones and iPod touches are able to connect to the WLAN secure with only their powers of AD.  They are then invited to accept the certificate and granted access to the WIFI secure.

    Our field machines require the certificate be installed via Group Policy, so I'm not sure how Apple devices are pulling down from the cert.

    Does anyone have any suggestions on how to do to block this behavior?  We would like that these devices use only access visitor web-auth.

    The solution has been added in the below mentioned document: -.

    https://supportforums.Cisco.com/docs/doc-21756

    This should help:

    http://support.Microsoft.com/kb/929847

  • Using Unified Wireless network needed emergency assistance

    Dear community

    I need urget for a unified network wireless installation assistance to deploy in a college

    What in fact is the senario for this network I have a 5500 WLC and 12 lwapp 1252 APs series for this Ant of deployment, it is already a local network existing

    network to connect with him the new unified wireless configuration.

    This is above the proposed topology.

    I need help for this installation as

    I know the controller to do basic configuration but I don't really know of GUI, what steps I must configure the controller for each access points as you can see above I have three floors for the construction and I want given three SSIDS as use of contractors and comments for each floor and how to configure the encryption type and a shared key for each SSiD.

    and what I have to configure for APs to join them with controller

    and hoe to set RF grouping for each floor.

    Please I need urgent reply because I have tp finish this set up everything in a weekonly

    Thans in advance.

    Hello

    Wat ever you want... the link below has everything... Just click on the stuff you neeed FRO mthe menu and this will do it for you!

    http://www.Cisco.com/en/us/docs/wireless/controller/7.0/Configuration/Guide/C70.html

    1 > set up wireless LANs.

    2 > set up the consolidation of the AP.

    Concerning
    Surendra

  • I have a Proxy Server that uses a self-signed certificate, and I can't accept this certificate from Firefox

    I have Firefox installed 37.0.1 on OpenSuse 13.2. I have a proxy server that uses a self-signed certificate, and I tried to add my certificate to the list of authorities and to check all the option displayed to be wz trust no chance.

    I tried to restart firefox, but it did not help.

    I did the same steps in chrome and it works fine.

    appreciate any help.

    After removing my .mozilla in my home directory. Add the certificate to the list of authorities in fact work.

  • Problem with certificate and the exception is not available

    So, here is my problem I am trying to connect to a secure server. When I do this, I get to a page telling me the browser appears not that the server is secure and that the certificate is old.

    When I click on the button "Add an exception" a small window opens saying the certificate is new safe and I can't add an exception.

    The exeption box is grey so I can't click in and the button 'Add exception' is olso gray so I can't click on it. I click on the button "Cancel" and return to the page telling me the server is not sure.

    How can I go about solving this problem?

    Check the date and time of the clock on your computer: (double) click on the clock icon in the Windows taskbar.

    Find out why the site is not approved, then click on "Technical Details to expand this section.
    If the certificate is not reliable because no issuer channel was provided (sec_error_unknown_issuer) and then see if you can install the intermediate certificate from another source.

    You can retrieve the certificate and check details such as WHO issued the certificates and the expiration dates of certificates.

    • Click on the link at the bottom of the error page: "I understand the risks".

    Let Firefox recover the certificate: "Add Exception"-> "get certificate".

    • Click on the "view..." button. "and inspect the certificate and the Coachman, who is the issuer of the certificate.

    You can see more details like the intermediate certificates that are used in the details pane.

    If "I understand the risks" is missing, this page can be opened in a (i) frame and in this case, try the shortcut menu and use "Frame this: Open image in New Tab".

    Note that some firewall monitors connections (sure) and that programs like Sendori or FiddlerRoot can intercept connections and send their own certificate instead of the certificate of the Web site.

  • I need to create public and private keys for the security certificate and I can not find the certificate. Where is he?

    I bought a security certificate, and the site tells me that it has been installed successfully. I need to export the certificate so that I can create public and private keys, but I can't find the certificate to do so.

    Firefox (Firefox Orange) > Options > Options > advanced > Certificates > authorities > export

  • Problem with Firefox 13 certificate and secure Web sites

    Hello

    I am using Windows 7 32 bit on a Dell laptop.

    Everything was going well until I've upgraded to Firefox 13 a few days ago. I can't not to connect to Web sites secured like Gmail, Amazon, etc.

    It works perfectly fine in all other browsers is not an OS related issue.

    I use ESET Smart Security 6.0 beta and he hasn't behaved badly with any application.

    I tried the basic solutions as compensation network, the browser history cache, etc. I also reinstalled 13 (own) of Firefox.

    There is no modules or extensions installed in Firefox. The Proxy is set to 'No Proxy'.

    Each click in gmail throws an "Untrusted" error, even if I get certificates and store them permanently.

    I also tried tweaking all: variable config like below, but did not work.

    Browser.XUL.error_pages.expert_bad_cert = true

    Please help because it is extremely difficult to work with these problems.

    Thank you
    Anand

    Bingo!

    I removed SSL scanning from ESET 6.0 and re-installed all the more recent Windows updates. Everything works fine now.

    Thanks for your help!

    Best wishes, Anand

  • energy saving with keyboard and mouse wireless

    Hello

    It is from Inma

    Whenever I try to save energy in the keyboard, I have to turn off the computer and the wireless mouse. Is there a way to do all the time? Thank you!

    Hi there migmartinez,

    Looks like you are looking to save your keyboard and bluetooth mouse battery by turning off your computer. You can turn off your mouse with the button on the bottom. When you turn back automatically re - will pair with your computer:

    From: http://www.apple.com/shop/product/MLA02LL/A/magic-mouse-2

    Your keyboard has not, however, a stop button. You can remove the batteries, but I can see how that might be inconvenient:

    Keyboard Apple wireless, mouse, and Trackpad: how to install batteries

    Thank you for using communities of Apple Support.

  • Re: Equium L40 - Windows 7 and the wireless switch

    I upgraded my Equium L40 to Windows 7 and now, wireless equipment and F8 function switch switch the WLAN on and outside. It is permanently.

    Also, even if it is enabled in the Windows 7 power options, close the lid won't be thecomputer to sleep. If I close it turns off the screen but doen't make Windows 7 options.

    When I upgraded to Windows 7, I chose the option to do as a new installation and therefore lost my Vista installation.

    I have download all the drivers for Windows 7 on the Toshiba site, even if there were not many.

    Is there something else I need to do for the WLAN switch and cover works with Windows 7? Any help gratefully received.

    See you soon,.

    Ray D

    > I have download all the drivers for Windows 7 on the Toshiba site, even if there were not many.
    What L40 you exactly (L40 - xxx). I just want to check if your model of laptop is fully supported for Win7.

  • Tablet PC and projector wireless recommendations

    I want to try a tablet PC and wireless projector to replace an interactive whiteboard, implemented in a classroom that has wireless LAN access.
    Any tips or questions? Any recommendations for brands and models?

    No problem with slowness when using multimedia? Thanks :)

    Hi mate,

    I put t know what you expect of new tablet PC and projector wireless, but about the tablet-PC, you should have a look on the Toshiba Portege series. They are very good and have a nice design. Here, you can check the specifications:
    http://EU.computers.Toshiba-Europe.com > laptops & Netbooks > Portege

    About the spotlight, I founded an interesting page:
    http://www.Toshiba-projectors.com

  • Driver Bluetooth Win7 and s004TX wireless button driver

    I have Compaq s004TX but I can not bluetooth to work. And there's no driver available on the official website

    http://h10025.www1.HP.com/ewfrf/wc/softwareCategory?OS=4063&LC=en&cc=in&DLC=en&sw_lang=&product=7308...

    and the wireless button does not work either.

    They have driver for bluetooth and wireless button for win8 but not for win7.

    How can I make it work?

    Hello:

    Your model uses much more recent Ralink WLAN and BT drivers when the review of material maps have changed.

    Wireless:

    http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/psi/swdDetails/?spf_p.tpst=swdMain&spf_p.prp_swdMain=wsrp-navigationalState%3DswItem%253Dob_133279_1&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

    BT:

    http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/psi/swdDetails/?spf_p.tpst=swdMain&spf_p.prp_swdMain=wsrp-navigationalState%3DswItem%253Dob_130390_1&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

    Button wireless drivers are s/w for Windows 7.

    For other drivers, you must, use those of the HP Probook 450 G1, except the audio, BIOS and Firmware files.

  • Add internal Bluetooth and/or Wireless N dual channel HP dv4-2164us

    My computer is currently under warranty, so I'm not eager to open the machine until the computer comes out of the warranty.  Before opening the machine, so these are my questions:

    Quick questions for gurus.

    I think to add internal bluetooth and/or Wireless N dual channel my computer to HP dv4-2164us.

    1. My MB has connections to add a separate internal bluetooth card?
    2. To clarify the question 2... If the MB CAN normally do, HP is usually to have the connectors removed from the Mo for these types of potential improvements?
    3. What bluetooth card do you recommend?
    4. I currently have 2.4 GHz wireless n.  A different card support double n AND bluetooth would be a better solution?
    5. If Yes to question 4 What considerations such as antenna or other changes should be aware of them before the decision?
    6. All this that imagine you being to consider

    Thanks in advance!

    FYI, the Bluetooth does not have an antenna.

  • How to validate windows XP and get wireless to work on compaq mini 110 c-1001nr?

    My father (86) crashed his compaq mini and it was all blue screen, so I tried to use this recovery software to restore the factory settings, but nothing has worked. a friend suggested from scratch, so to format hard drive and reinstalled windows Xp for him. He worked for a month and now ask you the key product, but when we enter the key at the bottom of the computer it says invalid.

    I tried HP support, but I need to connect to the internet to download anything and the wireless is not working.what can I do now?

    When I start it up it says windows xp starts and says "the copy of Windows must be activated before you can connect" then we are stuck in the entrance of your product keys page. I click on phone, given that my key does not work and called the number he says and will not let me reset it.

    Give Microsoft activation will not take the "reset" answer, youre activation, do not reset.

    That # is 8885712048

    In addition, change "internet connection" in the Control Panel, locate the properties of the material change

    In addition, change 'internet options '.

    In addition, youre pc hardware software/drivers (if based on intel) intel.com will have the necessary downloads,.

    Search/drivers/software support, look for the update utility

  • Why can't I just print and fax wireless?

    I tried everything and still can't print and fax wireless

    Hello

    I have tried everything and you don't find what your printer, your PC/laptop and his BONES!

    Kind regards.

  • his silence and buttons wireless seems to have been disabled

    I accidentally spilled coffee on my notebook Pavilion dv6 notes and in a frantic attend to mop up the liquid, I must have somehow disabled the silent sound and buttons wireless while wiping the keys.  They worked before the oil spill, but not after.

    Also, as an aside, the left shift key works more so.  It can be bypassed, but it would be nice if the worked.  Any help would be appreciated

    Hey @306hp ,.

    Thank you for visiting the Forums HP's Support and welcome. I read on your HP laptop and get a fix of coffee. Try perform a reset. When you perform a hard reset note remove all USB devices and remove cards memory card reader location. Disconnect all non-essential devices.

    If that doesn't help try to turn on the computer, on which you begin to press F11 repeatedly until the menu opens. You can do a System Restore. System restore allows you to convert any changes that might have happened after the accident.

    I would use q-tips to ear slightly moistened to clean around the stuck key. Coffee gets in it a causes it to stick.

    Hope it will be useful.

    Thank you.

Maybe you are looking for

  • How to get NB100-11R automatically connect to the WLan on logon

    I just bought a netbook NB100-11R.First time that I started it, I went into the network administration panel to set up a wifi access.She had detected my wireless network, so I entered the WPA password and it connected correctly. I saved these paramet

  • With the help of a knot of property for multiple controls/indicators

    Question for you all the gurus of LabVIEW.  Is there a way to create 1 node property that is used for several indicators?  For example, if I wanted to display the same value on 10 different indicators, using the node property - value function do I ne

  • All-in-one HP Photosmart C5300 found series driver

    Hello! I have a HP Photosmart C5380 all-in-One hooked up with my Airport wireless at home station, from where we can print from any laptop paired with it. When you install Hello to a new workstation based on windows 8, it identifies the series C5300

  • I can't change my admin password, even though I am connected to the account now.

    Last week I changed my Admin password to something a lot more time with little maintenance, however I do not remember it now, so my question is, what can I do to reset it back to the old. Unfortunately, I forgot to make a recovery disk. I tried to re

  • Re vita home Premium software installation

    Hello I got my pc repaired and told me that I have to recharge using the disc that came with the device and put the code in who is with her. I did it and pc works now, but after a few days it came with this blue screen which I never saw before saying