What's new

wpa2 enterprise - obtaining a certificate?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

ynohtna

Regular Contributor
I've been trying to get my wife's phone set up on her university network and all the research I've seen about wpa2-enterprise is that a certificate is needed. For some reason the certificate doesn't auto download for the phone and IT doesn't have a clue about a certificate.

I have a laptop that connects fine. My question is, how do I get the cert off my laptop? I imagine it's a file even when 'installed' on the laptop?

Thanks!
 
Certificate is needed if you accidentally have 802.1X (RADIUS) authentication enabled. Some versions of Windows have it enabled by default. It's buried in the advanced tab of the WiFi config via the Control Panel/network devices.
 
Last edited:
Can't you get help from the University's IT help desk? This can't be a unique problem.
 
yea the work IT guys are not going to support anything that's not official I guess... It's kind of limiting but it absolves them of responsibility.

I was combing through the wifi AP settings on the laptop and saw the section for certificates and it's thawte premium security ca or something. The phone has the same one! So I guess a certificate file is not needed? I also saw settings for the authentication server I guess? I put that in the "Realm" section of the phone.

There's is a user/pass log in when they access the wireless so and I know mschap v2 is used. I'm just not sure what PEAP version is in place. The phone lists V0, V1, V2... and V2 was not enabled. I've enabled all 3 but I prefer to have it explicitly set and others.

Anyways, I'm hoping everything is manually configured properly and will just work lol

Any other thoughts from what I just posted? Is my assumption about the certificate correct?

Thank you
 
Try with just PEAP V0, it uses MSCHAP v2.

PEAP V1 uses EAP-GTC and is rarley used(not even Windows latest client OS' have support for it).

If everything was there to begin with, what prevented it from connecting? Was it Active Directory not allowing both laptop and phone to authenticate as the same user?
 
Last edited:
Thanks for working through the thought process with me!

The problem was there was no error messages coming from the phone, so had no idea what the problem was. I put it down to PEAPV0 only and unchecked the other... re-entered the log in info (username instead of domain\username) and my wife proclaimed she was able to surf the internet on her phone!

So it looks like it was simply a matter of knowing what to put. It's stupid that in today's time, it couldn't be auto config'd on the phone!
 
Similar threads
Thread starter Title Forum Replies Date
tonymet WPA2 Shared Secret Rotation: How to avoid downtime? General Wireless Discussion 13

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top