cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1204
Views
1
Helpful
4
Replies

Native Supplicant Profile With Multiple SSIDs Using EAP-TLS Auth

Scott Gillies
Level 1
Level 1

Hi

I have a Native Supplicant Profile that supports the deployment/on-boarding of a client device with 2 SSIDs both using EAP-TLS authentication.

On-boarding requires the client to initially authenticate via their Active Directory credentials which then pushes them to Client Provisioning.

When the on-boarded client tries to connect to either SSID it always performs EAP-TLS using the same certificate.

How do I get the client device to use the correct certificate with the correct SSID?

Thanks in advance.

1 Accepted Solution

Accepted Solutions

Apple configuration profiles for Wireless on iOS and macOS allow multiple SSIDs and, if cert-based auth, each with its own certificate. The same might not work well on other client OS's.

View solution in original post

4 Replies 4

Jason Kunst
Cisco Employee
Cisco Employee

The clients are set to use a certificate for the specific profile and ssid.

AFAIK We don’t support having multiple certs deployed as part of one profile

hslai
Cisco Employee
Cisco Employee

If this is about Windows Native Supplicant, then I do not believe it ties the network profiles with particular personal certificates so that might be expected behavior.

Scott Gillies
Level 1
Level 1

Hi

Please see image, appropriately redacted, of the Native Supplicant Profile template. It allows you to add multiple SSIDs (Wireless Profiles) to the profile template using (I assume) different Certificate Templates, in this case we have 2 different EAP Templates (names not fully shown).

Native Supplicant Profile-SSID.bmp

So what does "Multiple SSIDs" imply?

Apple configuration profiles for Wireless on iOS and macOS allow multiple SSIDs and, if cert-based auth, each with its own certificate. The same might not work well on other client OS's.