Hi All.
There is a lot of info over the years about 802.1x, and I'm not sure where I am going wrong. Some threads suggest that computer authentication with Casper is broken, others say you NEED an AD certificate, others say you don't.
Could someone just verify what I should be doing to get this working? Currently we have a computer level configuration profile.
Casper 9.97, Mac OSX 10.11
NETWORK
Network Interface: Ethernet
Use as a Login Window configuration - Enabled
Protocols TTLS & PEAP
Use Directory Authentication - Enabled
Inner Authentication - MSCHAPv2
Trust - Both Certificate (Intermediate and Root) selected.
Certificate Common Name: *.ourdomain.com
CERTIFICATE
2 Certificates added - Root and Intermediate
That's it.
It initially connects to Radius, does initial handshake, but the Macs stop responding when trying to do proper authentication as the computer account. If I log into a device and have a look at the network settings, 802.1x just says "connecting" for a very long time. If I stop and use my own credentials, all is fine... so I know it's an issue with the Mac passing the computer credentials.
Suggestions very welcome :)


