Reply
Thread Tools
Posts: 52 | Thanked: 4 times | Joined on May 2007 @ Denver, CO
#1
Anyone get WPA with EAP working using PEAP with Certificate.

WPA works fine for my user PSK just not certs.

I have loaded the company certificate on my N800 and it loads find but does not come up under "Select Certificate".

I have the lastest firmware loaded on my N800

Under "Certificate Manager" its listed under "authorirties" and if I view the cert I says Purpose: E-Mail: Yes, Browser: Yes, WLAN: yes.

I don't get the options to select this under WLAN though. What gives?
Please help...
 

The Following User Says Thank You to witznitz For This Useful Post:
Posts: 24 | Thanked: 0 times | Joined on Jun 2007
#2
Not exactly the answer you're looking for, but maybe this will help somehow....

It's working for me WPA with EAP and PEAP, but my certificate is set to None, and EAP method is set to EAP GTC.
 
Posts: 52 | Thanked: 4 times | Joined on May 2007 @ Denver, CO
#3
I need to use a certificate. I think its a bug, there is no way to get the certs to show up under Select Cert.
 
Posts: 474 | Thanked: 30 times | Joined on Jan 2006
#4
Extremely longstanding non-implemented feature.
 
Posts: 2 | Thanked: 0 times | Joined on Jul 2007
#5
If anyone can figure out how to get the certs implemented, i'd probably owe them my life (this is suicidally maddening).

My school uses WPA TKIP PEAP EAP-MSCHAPv2 with a Thawte cert that is included on the N800 but inaccessible from connectivity settings. Can I get network-manager or something to run, or do I need to run a separate OS to get certed PEAP on an N800?

I'm reduced to using the old system, an open wep then using VPN. Slow, loses vpn if i move to another access point, horrible. When I need to move between classes every hour and just want to pop this up to check RSS and play music between classes, having a campus-wide network that disconnects every 15 feet to hit a new AP isn't going to work for me.

Please tell me i'm a fool and there's some way to get WPA PEAP.
 
Posts: 39 | Thanked: 2 times | Joined on Jun 2007
#6
Are you using WPA or WPA2? Also, is your certificate a personal certificate or a root certificate?

The company I work for just upgraded the WLAN to use WPA2 with PEAP and EAP MSCHAPv2.

The certificate I was provided with is a root certificate. When the certificate is installed, it shows up under the Authorities tab but not the User tab (in Certificate manager). I enabled all three Trust options.

For the Connection setup:
page 1: Connection type = WLAN
page 2: Network mode = Infrastructure; Security method = WPA with EAP
page 3: EAP type = PEAP
page 4: Select certificate = None; EAP method = EAP MSCHAPv2
page 5: You can enter your login information if you don't want to log in manually each time
page 6: Click "Advanced" button
Other tab: Enable "WPA2-only mode"
EAP tab: Enable "Use manual user name"; enter your "Manual user name"; Disable "Require client authentication" (I thought I had this one enabled initially, but it will now only work if disabled)

This works for me. Let me know if you have any questions about my setup.
 
Posts: 35 | Thanked: 1 time | Joined on Nov 2006 @ Madrid, Spain
#7
If I had configured a user in a NT Domain like this:

user: user12
password: passwd123
Domain: Enterprise

How do I configure the user for MSCHAPv2 authentication?

In the example, must I write user12, user12@Enterprise, Enterprise\user12 or something similar to these? (I think I probe all combinations and it didn't work)

Thank you very much in advance.
 
Posts: 19 | Thanked: 1 time | Joined on Dec 2007
#8
Originally Posted by Rtalian View Post
Are you using WPA or WPA2? Also, is your certificate a personal certificate or a root certificate?

The company I work for just upgraded the WLAN to use WPA2 with PEAP and EAP MSCHAPv2.

The certificate I was provided with is a root certificate. When the certificate is installed, it shows up under the Authorities tab but not the User tab (in Certificate manager). I enabled all three Trust options.

For the Connection setup:
page 1: Connection type = WLAN
page 2: Network mode = Infrastructure; Security method = WPA with EAP
page 3: EAP type = PEAP
page 4: Select certificate = None; EAP method = EAP MSCHAPv2
page 5: You can enter your login information if you don't want to log in manually each time
page 6: Click "Advanced" button
Other tab: Enable "WPA2-only mode"
EAP tab: Enable "Use manual user name"; enter your "Manual user name"; Disable "Require client authentication" (I thought I had this one enabled initially, but it will now only work if disabled)

This works for me. Let me know if you have any questions about my setup.
I believe the certificate I had to generate for use is a private certificate, not a root certificate. Does this make any difference?

This did not work for me.

Even though it's set to prompt me for my password for the connection I get "Authentication Failed" and never even see a prompt.
 
Posts: 19 | Thanked: 1 time | Joined on Dec 2007
#9
This seems to be documented here: https://bugs.maemo.org/show_bug.cgi?id=327

But the last post by a Nokia person seemed to imply he didn't think it was a bug because the certificate the person posted was not the kinda that is intended for that dropdown menu. Submitting a personal certificate to the bug report may allow it to be fixed at last.
 
Posts: 13 | Thanked: 0 times | Joined on Nov 2007
#10
Originally Posted by delusional1337 View Post
If anyone can figure out how to get the certs implemented, i'd probably owe them my life (this is suicidally maddening).

My school uses WPA TKIP PEAP EAP-MSCHAPv2 with a Thawte cert that is included on the N800 but inaccessible from connectivity settings. Can I get network-manager or something to run, or do I need to run a separate OS to get certed PEAP on an N800?

I'm reduced to using the old system, an open wep then using VPN. Slow, loses vpn if i move to another access point, horrible. When I need to move between classes every hour and just want to pop this up to check RSS and play music between classes, having a campus-wide network that disconnects every 15 feet to hit a new AP isn't going to work for me.

Please tell me i'm a fool and there's some way to get WPA PEAP.

My school uses the same thing ( I remember it was Thawte Cert some point of time..., but in *nix I dont have to do anything, just use the cert they provide in NetManager). I can connect using 0s2007 and had issues w/ os2008. I have not tried in a while, mostly will not till skype is for prime time on os2008.

http://www.internettablettalk.com/fo...77&postcount=6

Please look at this link and tell me if there is some thing similar, if so I think I can help w/ os 2007.

Last edited by sanraj83; 2007-12-11 at 22:15.
 
Reply


 
Forum Jump


All times are GMT. The time now is 16:33.