<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looking at the document, I in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666208#M17835</link>
    <description>&lt;P&gt;Looking at the document, I see something called OpenSSL. &amp;nbsp;Do I get a certificate from that website or could you recommend a well known provider. &amp;nbsp;Not much experience with certificates. &amp;nbsp;Just started about 6 months ago on the guest wireless. &amp;nbsp;We have had wireless for the employees for years but guest is new.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Feb 2015 15:50:01 GMT</pubDate>
    <dc:creator>kdgattis</dc:creator>
    <dc:date>2015-02-13T15:50:01Z</dc:date>
    <item>
      <title>Your connection 1.1.1.1 is not private</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666206#M17833</link>
      <description>&lt;P&gt;I have a cisco controller 2504. &amp;nbsp;We have&amp;nbsp;guest internet plug into port 2 of the controller. &amp;nbsp;I have layer 3 web authentication set up in which guest see a web site and type a user name and password to get on the guest wireless internet. &amp;nbsp;However, when I connect I get this every time, "Your connection is not private 1.1.1.1, NET:ERR_CERT_AUTHORITY INVLAID, This server could not prove that it is 1.1.1.1; its security certificate is not trusted by your computer operating system. &amp;nbsp;I'm unsure on setting up certificates, but I do see one on the controller as 1.1.1.1. &amp;nbsp;If I export it to my computer and install as a trusted certificate then it works, but how do I get the guest pc's to trust this controller. &amp;nbsp;Do I need a public certificate?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666206#M17833</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2021-07-05T09:30:08Z</dc:date>
    </item>
    <item>
      <title>if you want the guest to not</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666207#M17834</link>
      <description>&lt;P&gt;if you want the guest to not get that cert warning, then you would want to get a certificate from a well known provider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/70584-csr-wlc-00.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you do this, you also need to make sure that the DNS server you give to the guests can resolve the Virtual interface IP/name&amp;nbsp;to the name that you put in the certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 15:37:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666207#M17834</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2015-02-13T15:37:11Z</dc:date>
    </item>
    <item>
      <title>Looking at the document, I</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666208#M17835</link>
      <description>&lt;P&gt;Looking at the document, I see something called OpenSSL. &amp;nbsp;Do I get a certificate from that website or could you recommend a well known provider. &amp;nbsp;Not much experience with certificates. &amp;nbsp;Just started about 6 months ago on the guest wireless. &amp;nbsp;We have had wireless for the employees for years but guest is new.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 15:50:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666208#M17835</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T15:50:01Z</dc:date>
    </item>
    <item>
      <title>openSSl is just a program to</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666209#M17836</link>
      <description>&lt;P&gt;openSSl is just a program to let you build the request and combine the files you get back from the provider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for well known, Thawte, Verisign, GoDaddy...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 15:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666209#M17836</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2015-02-13T15:55:52Z</dc:date>
    </item>
    <item>
      <title>Its a bit involved .. Create</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666210#M17837</link>
      <description>&lt;P&gt;Its a bit involved ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create CSR&lt;/P&gt;&lt;P&gt;Get CSR signed&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bind the CSR to private pem&lt;/P&gt;&lt;P&gt;Upload to the controller&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure the cert name resolve to 1.1.1.1 (virtual ip address on WLC).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add A record like guest.yourdomain.com to resolve to 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do this for customers all the time.. ping dcmc.guestnetwork.org&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 15:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666210#M17837</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-13T15:59:48Z</dc:date>
    </item>
    <item>
      <title>Another newbie question,  Why</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666211#M17838</link>
      <description>&lt;P&gt;Another newbie question, &amp;nbsp;Why do I have to have a certificate for this to work? &amp;nbsp;I guest I'm not understanding the certificate. &amp;nbsp;For example, at my house the internet comes in, I have it plugged into a wireless router don't need one to connect to the internet. &amp;nbsp;At our facility the internet comes in, plug into a cisco RSV I think, then plug into port 2 on the controller. &amp;nbsp;The web address it redirects them to is our web page &lt;A href="https://community.cisco.com/www.autumncorp.com" target="_blank"&gt;www.autumncorp.com&lt;/A&gt; in which is provided by BizCom. &amp;nbsp;Wouldn't the cisco controller basic certificate I see under Web Auth, certificate locally generated be trusted, since it's from cisco. &amp;nbsp;I thought certificate were for a business which house their own web servers. &amp;nbsp;Sorry for some many questions, trying to understand when I need a certificate and when I don't.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 16:15:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666211#M17838</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T16:15:10Z</dc:date>
    </item>
    <item>
      <title>Can I generate CSR on my</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666212#M17839</link>
      <description>&lt;P&gt;Can I generate CSR on my windows 2008 CA server, or does it have to be public from a third party?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 16:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666212#M17839</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T16:49:08Z</dc:date>
    </item>
    <item>
      <title>No since your guest won't</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666213#M17840</link>
      <description>&lt;P&gt;No since your guest won't have your root. You need to have a pubic ..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 16:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666213#M17840</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-13T16:51:42Z</dc:date>
    </item>
    <item>
      <title>Ok, another newbie question.</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666214#M17841</link>
      <description>&lt;P&gt;Ok, another newbie question. &amp;nbsp;Do I have already a certificate from our website "www.autumncorp.com" from BizCom. &amp;nbsp;Since BizCom houses our website wouldn't that be trusted. &amp;nbsp;I'm I looking at this wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 17:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666214#M17841</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T17:03:02Z</dc:date>
    </item>
    <item>
      <title>Who signs your public certs ?</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666215#M17842</link>
      <description>&lt;P&gt;Who signs your public certs ? Bizcom sound like a web hosting company.. They don't sign certs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;You would create a CSR in openssl and fill out the cert info. The common name you could use guest.autumncorp.com.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 18:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666215#M17842</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-13T18:00:48Z</dc:date>
    </item>
    <item>
      <title>Nobody signs public certs.  I</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666216#M17843</link>
      <description>&lt;P&gt;Nobody signs public certs. &amp;nbsp;I have a CA on our active directory server. &amp;nbsp;I guess so far we haven't needed one until now. &amp;nbsp;Bizcom is a web hosting and email company.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 19:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666216#M17843</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T19:07:18Z</dc:date>
    </item>
    <item>
      <title>Yea, so whoever manages you</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666217#M17844</link>
      <description>&lt;P&gt;Yea, so whoever manages you domain or maybe even the web host can get you a signed cert. Like for me I own guestnetwork,org. I go through godaddy .. I&amp;nbsp;provide them my CSR and they burn me the cert tied to my domain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is why I created guestnetwork.org I&amp;nbsp;handle this entire process for customers; csr,cert,A record etc ... It can be a pain for some folks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 19:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666217#M17844</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-13T19:20:35Z</dc:date>
    </item>
    <item>
      <title>autumncorp.com is our domain</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666218#M17845</link>
      <description>&lt;P&gt;autumncorp.com is our domain name and BizCom manages it. &amp;nbsp;Do I need to get up with them to get a certificate for our domain and install that&amp;nbsp;certificate on my controller. &amp;nbsp;Another question, if I redirect them to another web site like &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; would that bypass the certificate error. &amp;nbsp;Also, how many certificates do I need? &amp;nbsp;Just one, or one for each guest logging in. &amp;nbsp;Not seeing this message on phones or ipads just computers.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 19:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666218#M17845</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T19:48:21Z</dc:date>
    </item>
    <item>
      <title>You create the CSR in open</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666219#M17846</link>
      <description>&lt;P&gt;You create the CSR in open SSL. You give your CA the CSR and they will burn you the cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you take the root, chain,&amp;nbsp;device certs&amp;nbsp;then&amp;nbsp;bind it to the pem in open ssl.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once that is done then you upload to the controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure you use a version of openssl lower than 1.0v.&lt;/P&gt;&lt;P&gt;If you want a guest page then you need the cert. Redirects happen AFTER the page pop up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You only need one and you can put on your different controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you anchoring ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Delete the SSID from your iPad and try it again. Looks like you may have accepted the cert the first time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 19:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666219#M17846</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-13T19:52:48Z</dc:date>
    </item>
    <item>
      <title>Thanks, alot for all your</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666220#M17847</link>
      <description>&lt;P&gt;Thanks, alot for all your help. &amp;nbsp;If I only need one certificate for all my controllers how much does a certificate usually cost? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 20:43:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666220#M17847</guid>
      <dc:creator>kdgattis</dc:creator>
      <dc:date>2015-02-13T20:43:22Z</dc:date>
    </item>
    <item>
      <title>No worries.. Certs you buy in</title>
      <link>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666221#M17848</link>
      <description>&lt;P&gt;No worries.. Certs you buy in time .. Like one year is $75 or cheaper .. depends which CA you use to sign.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feel free to support the rating system if any of this is helpful!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 20:55:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/your-connection-1-1-1-1-is-not-private/m-p/2666221#M17848</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-13T20:55:13Z</dc:date>
    </item>
  </channel>
</rss>

