04-03-2019 01:24 AM - edited 07-05-2021 10:11 AM
Hi guys, I'm just starting to configure a WLC 5508 for employee wifi access. I did the LDAP setup, configured a local PEAP profile etc.
When I try to setup the wireless connection on my smartphone, I get a certificate warning about the self-signed Cisco certificate of the WLC. Authorizing it the connection is established. What kind of certificate do I need to install (and how) in the WLC to avoid the warning? I'd like to create an error free procedure for my users, the ssl warning could create some unnecessary panic...
PS
I already changed the web certificate with a valid one (I used a public wildcard certificate and mapped the WLC in our DNS - we use split technique - to an FQDN of the domain covered by the certificate).
bye, Dario
Solved! Go to Solution.
04-04-2019 06:43 AM - edited 04-04-2019 06:45 AM
Even then you get asked, because a rogue person could create his own Radius and do an MitM attack. The only way to validate this as an end user, is by validating the certificate (thumbprint) presented by the radius server and shown to the end user with the one written down in the manual of the SSID. That or use an MDM solution.
Worse, some clients don't even allow a connection if the certificate root isn't known and trusted by the client (which at least protects you from MitM with not signed certificates).
04-03-2019 06:19 AM
04-04-2019 05:23 AM
04-04-2019 06:01 AM
04-04-2019 06:43 AM - edited 04-04-2019 06:45 AM
Even then you get asked, because a rogue person could create his own Radius and do an MitM attack. The only way to validate this as an end user, is by validating the certificate (thumbprint) presented by the radius server and shown to the end user with the one written down in the manual of the SSID. That or use an MDM solution.
Worse, some clients don't even allow a connection if the certificate root isn't known and trusted by the client (which at least protects you from MitM with not signed certificates).
04-04-2019 07:21 AM
07-01-2019 02:21 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide