Application Note. Onsight Device Certificate Management



Similar documents
Connecting to Secure Wireless (iitk-sec) on Fedora

Automatic Setup... 1 Manual Setup... 2 Installing the Wireless Certificates... 18

Airnet-Student is a new and improved wireless network that is being made available to all Staffordshire University students.

CruzNet Secure Set-Up Instructions for Windows Vista

How to connect to NAU s WPA2 Enterprise implementation in a Residence Hall:

How to Access Coast Wi-Fi

Instructions for connecting to winthropsecure. Windows 7/8 Quick Connect Windows 7/8 Manual Wireless Set Up Apple Quick Connect Apple Settings Check

How to connect to the diamonds wireless network with Vista.

How To Connect To A Wireless Network On Windows 7 (Windows 7) On A Pc Or Mac Or Ipad (Windows) On Pc Or Ipa (Windows 8) On Your Computer Or Mac (Windows). (Windows.7) On An

Mac OS X Secure Wireless Setup Guide

How to connect to VUWiFi

Instructions for accessing the new TU wireless Network

INFORMATION SYSTEMS SERVICE NETWORKS AND TELECOMMUNICATIONS SECTOR

Connecting to UNOSECURE using Windows 7

Windows 8 & RT Wireless Configuration For NCC Student Owned Laptops

Wireless Network Configuration Guide

MC3WAVES Wireless Connection Wizard

Network Services One Washington Square, San Jose, CA

Massey University Wireless Network - Client

Connecting to the Rovernet WPA2 Secured Wireless Network with Windows 7

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows Mobile 6.1

Connec ng to Northwest s WIFI with Windows 7

Extension Wireless Access (EWA) v2.0

Setting up SJUMobile (Wireless Internet Access for personal devices)

Eduroam wireless network Windows Vista

Configuring Windows 7 to Use Encrypted (WPA-E) Wireless Services a...

User Guide for eduroam

Internet access system through the Wireless Network of the University of Bologna (last update )

Connecting to the University Wireless Network

Using WPA Enterprise on Windows XP to Access Cleveland State University s Wireless Network (WoWnet)

RSC-Secure-Wireless provides...

IT Quick Reference Guides Connecting to SU-Secure using Windows 8

Instructions for connecting to the FDIBA Wireless Network. (Windows XP)

WiFi troubleshooting. How s your WiFi signal? Android WiFi settings. ios WiFi settings

WiFi Internet Access. Windows XP Setup Instructions. Please Return After Use. Produced Oct 2010

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows 7

GPC JagTalk Secure Wireless Network. Connection Instructions

Windows Vista and Windows 7 Wireless Configuration For NCC Faculty and Staff Owned Laptops

Configuring Eduroam in Windows Vista

ClickShare Network Integration

Massey University Wireless Network Client Configuration Windows 7

Internet Access: Wireless WVU.Encrypted Network Connecting a Windows 7 Device

Eduroam wireless network - Windows 7

Last Updated: January 23, FLCCsecure

Creating and Installing a Self Signed Certificate for PEAP/EAP-TLS Authentication

Configuring WPA2 for Windows XP

Eduroam wireless network Apple Mac OSX 10.5

How To Set Up Hopkins Wireless On Windows 7 On A Pc Or Mac Or Ipad (For A Laptop) On A Network Card (For Windows 7) On Your Computer Or Ipa (For Mac Or Mac) On An Ipa Or

Installation Guides - Information required for connection to the Goldfields Institute s (GIT) Wireless Network

WIRELESS SETUP FOR WINDOWS 7

Setting up Windows XP for WPA Wireless Access (ISU-OIT-WPA)

Wireless LAN Client Configuration Guide for Windows Configuring 802.1X Authentication Client for Windows 7

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

Eduroam wireless network Apple Mac OSX 10.4

Edith Cowan University Information Technology Services Centre

KU Information Technology provides wireless access for both the KU campus community and for guest users at many points across campus.

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows Vista

Massey University Wireless Network - Client Configuration Windows XP (Service Pack 2)

6. After connecting reopen the wireless connections window. Right click on RamNet and select properties. Page 2 of 7

AeroLab Wireless Network Code of Conduct. Connecting to the AeroLab Wireless Network

Configuring a Windows 2003 Server for IAS

ICT DEPARTMENT. Windows 7. Wireless Authentication Procedures for Windows 7 & 8 Users For Linux and windows XP users visit ICT office

Manually Configuring Windows Vista for Wireless PittNet

Manual Configuration Instructions

Configuring WPA-Enterprise/WPA2 with Microsoft RADIUS Authentication

Defiance College Networking Handbook

How to Connect to UAB s Wireless Networks

eduroam Overview and Device Configuration

How to set up Outlook Anywhere on your home system

Configuration Instructions for non-tcd users of the eduroam service

ipads and iphone 5 Connecting your own device to school wifi

A Division of Cisco Systems, Inc. GHz g. Wireless-G. USB Network Adapter with RangeBooster. User Guide WIRELESS WUSB54GR. Model No.

The back story of our Wireless (reading will help you understand what is going on in the building):

How to: Accessing the TU/e wireless network using Windows XP

Wi- Fi settings for Windows XP

Account Create for Outlook Express

Windows Vista: Connecting to the wireless network at Hood College

Basic Citrix Manual. Windows Computers and Laptops. Version 1.3. Created by Joshua Lindemann

How To Set Up Isu-Oit-Wpa On Windows 7 For Wireless Access (Isu- Oit- Wpa) On A Pc Or Mac Or Ipa (Windows 7) On An Ipa Or Ipac (Windows

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

Technical Certificates Overview

GSU JagTalk Secure Wireless Network. Connection Instructions

Wireless computer access at K-State

NetMotion + YubiRADIUS Quick Start Guide

Massey University Wireless Network Client Configuration Mac OS X

NotifyMDM Device Application User Guide Installation and Configuration for Windows Mobile 6 Devices

How to Connect to YaleSecure (Yale s secure wireless network)

Johns Hopkins

Configuring Windows 7 for eduroam at DkIT

CONNECTING THE RASPBERRY PI TO A NETWORK

Canterbury College Eduroam Wi-Fi Guide

eduroam wireless setup guide for Windows 7, XP and Vista

Phone: Fax: Box: 230

Meeting CJIS Advanced Authentication

Advanced Administration

Case Study - Configuration between NXC2500 and LDAP Server

YSU Secure Wireless Connect Guide Windows XP Home/Professional/Media Center/Tablet PC Edition

Step-by-step Guide for Configuring Cisco ACS server as the Radius with an External Windows Database

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

CONFIGURE THE BUCCANEER WIRELESS NETWORK USING WINDOWS HELP

Transcription:

Application Note Onsight Device Certificate Management

ONSIGHT DEVICE CERTIFICATE MANAGEMENT...3 Supported Certificate Formats:... 3 Stores List... 3 Importing Certificates:... 3 CERTIFICATE PACKAGES USING ONSIGHT MANAGEMENT SUITE...5 ONSIGHT DEVICE SIP REGISTRATION - SIP-TLS CHECK LIST:...5 ONSIGHT DEVICE WIRELESS NETWORK - EAP-TLS CHECK LIST:...6 ONSIGHT DEVICE WIRELESS NETWORK - PEAP CHECK LIST:...6 TROUBLESHOOTING...7 Application Note: Onsight Device Certificate Management - 2-2011 Librestream Technologies Inc.

Onsight Device Certificate Management X.509 Certificates are used to authenticate the identity of a User or Computer on a network. The Onsight Device supports using X.509 certificates for the following: 802.1X Wireless Network User Authentication e.g. TLS Server Authentication e.g. TLS or PEAP SIP-TLS encryption e.g. SIP Proxy Server registration Cisco Presence Server Authentication Supported Certificate Formats: Certificates:.cer contains certificate information with public a public key but not a private key. This is a generic extension that denotes a certificate. Server, Root Certificate Authority (CA), and Intermediate CA certificates can be in this format. It is commonly a plain text file and can be PEM, DER or Base 64 format. You can import these formats into the Windows certificate store. Public-Key Cryptography Standards (PKCS #12):.pfx,.p12 stores private keys with accompanying public key certificates, protected with a password based symmetric key. This format is generally only seen with a Client Certificate. Private Keys:.pvk private key for a User certificate. Stores List Certificates can be imported into the following three logical stores: My Certificates: contains individual certificates for users. Trusted Authorities: contains certificates from Trusted Root authorities. Other Authorities: stores all other certificate types, e.g. intermediate CA authorities. IMPORTANT: When using certificates the Onsight Device date and time must be accurate to allow successful authentication of the certificate. Importing Certificates: Copy the certificate you wish to install onto the Root directory of an SD card e.g. siphost.cer. Insert the SD card into the Onsight Device. Login to the Onsight Device and proceed Application Note: Onsight Device Certificate Management - 3-2011 Librestream Technologies Inc.

1. Go to the Main Menu and select Configuration. 2. Go to Security\Certificates and Press Certificates button. 3. Press Import button. Application Note: Onsight Device Certificate Management - 4-2011 Librestream Technologies Inc.

4. Select the certificate to import and press Import button. Note: you may be prompted to enter a password is the certificate is password protected. Certificate Packages using Onsight Management Suite Librestream s Onsight Management Suite can be used to manage your Onsight Mobile Devices and install certificates by creating certificate packages which are installed during a Software Update Job. The Onsight Management Suite Administrator creates a Certificate package which includes the certificate types supported by the Onsight Device. This package is then added to a Software Update Job that is pushed out to the devices when they connect to the Onsight Management Web Service. Each certificate is assigned to a Certificate Store and can be installed for use by all Users or a selected User only. Consult the Onsight Management Suite User Manual for details on creating Certificate and Software Update Packages. Onsight Device SIP Registration - SIP-TLS Check List: Confirm the correct date and time is set on the Onsight Device Install required X.509 certificates: SIP Server Certificate e.g. siphost.cer Set the Authentication Transport to TLS Application Note: Onsight Device Certificate Management - 5-2011 Librestream Technologies Inc.

Onsight Device Wireless Network - EAP-TLS Check List: Confirm the correct date and time is set on the Onsight Device Install required X.509 certificates: User Certificate Server Certificate Authority Root (if necessary) Correct WiFi security settings are entered on the Onsight Mobile o Encryption: TKIP or AES o Authentication: WPA or WPA2 o EAP type: TLS o Enter the user name of the Certificate under Configuration\Network\Wireless\Advanced\Wireless Network Properties\Properties\Authentication Settings\User Information o Press Select and tap on the correct Certificate to use for Authentication Onsight Device Wireless Network - PEAP Check List: Confirm the correct date and time is set on the Onsight Mobile Enter PEAP user name and password under Configuration\Network\Wireless\Advanced\Wireless Network Properties\Properties\Authentication Settings\User Information Verify the Validate Server check box is correctly set on the User Information page o If you are not validating the identity of the server uncheck Validate Server. o If you are validating the identity of the server check Validate Server and install the certificate for the server on the Onsight Device. Install required X.509 certificates: Server Certificate Authority Root (if necessary) Application Note: Onsight Device Certificate Management - 6-2011 Librestream Technologies Inc.

Correct WiFi security settings are entered on the Onsight Device. o Encryption: TKIP or AES o Authentication: WPA or WPA2 o EAP type: PEAP Troubleshooting 1. After following the setup steps the device still can t Authenticate: a. Is the user locked out because of too many authentication attempts? i. Time outs can occur during authentication attempts. E.g. Cisco Access Point controllers have an identity-request-timeout this can be modified to increase the timeout to prevent lockouts. If a user hasn t entered the username/password correctly and has to re-enter information the timeout can cause a lockout to occur. ii. Fix: Reset the PEAP user account at the RADIUS Server. 2. The username and password were entered in the correct location but the Network Information Dialog still prompts me for user name/password information. a. A typo may have occurred when entering the information. i. Press the Advanced button on the Wireless Information tab. Delete the SSID you are trying to connect to from the Preferred Networks list. Press OK. ii. Re-enter the information for the connection to the SSID including PEAP username/password information. 3. Has the date and time been reset? a. If the battery was allowed to drain the date and time may have been reset, check that the date and time are accurate. Application Note: Onsight Device Certificate Management - 7-2011 Librestream Technologies Inc.