Skip to main content
Answer

AD machine auth for 802.1x in 10.6.8 ?

  • January 9, 2013
  • 8 replies
  • 32 views

Forum|alt.badge.img+14

Has anyone successfully accomplished this? Works perfectly on 10.7+ using my config profile and $COMPUTERNAME for directory username.

Best answer by bbergstein

I just went through this....the easiest way to make this work was to change the template on the CA to include the UPN in the subject alternative name. This resolves the whole "username" thing, by including that in the cert itself. We just duplicated the standard computer template, named it "Giant Eagle Macs", and checked that box. Theres a pretty decent writeup of this on the macenterprise Google Group at https://groups.google.com/forum/?fromgroups=#!topic/macenterprise/K1M5wl_dloQ

8 replies

Forum|alt.badge.img+21
  • Honored Contributor
  • January 10, 2013

Sorry please explain I don't understand


Forum|alt.badge.img+23
  • Esteemed Contributor
  • January 10, 2013

He has a configuration profile that allows AD authentication over Wifi for user accounts. I've been trying to get one working reliably on 10.8 for a while now.

Andy, can you post exact details of the profile so we can have a look?


Forum|alt.badge.img+14
  • Author
  • Contributor
  • January 10, 2013

Profile looks like this

external image link

external image link

Again this working perfectly with our 10.7 and above clients. Thank you for help in advance!


Forum|alt.badge.img+7
  • Contributor
  • Answer
  • January 10, 2013

I just went through this....the easiest way to make this work was to change the template on the CA to include the UPN in the subject alternative name. This resolves the whole "username" thing, by including that in the cert itself. We just duplicated the standard computer template, named it "Giant Eagle Macs", and checked that box. Theres a pretty decent writeup of this on the macenterprise Google Group at https://groups.google.com/forum/?fromgroups=#!topic/macenterprise/K1M5wl_dloQ


Forum|alt.badge.img+23
  • Esteemed Contributor
  • January 12, 2013

Wait a moment ... I missed this earlier. Do config profiles even work on OS X 10.6.x ?


Forum|alt.badge.img+14
  • Author
  • Contributor
  • January 12, 2013

No .mobileconfig profiles do not work on 10.6.8 machines. @bbergstein. Thank you for the info. As we roll out the 802.1x wireless for students next school year we will be using this method.
Meanwhile this year while the 10.6.8 teachers are using the wpa2e EAP-PEAP wireless with a login window profile and a system profile containing a generic login authenticated user. We made some changes to that login user on the Aruba controler, that we think were causing issues. Long story short we were making this way more complicated than it needed to be. Thanks for the cert info again.


Forum|alt.badge.img+13
  • Contributor
  • March 13, 2013

Hi Andy, I'm trying to get the machine authentication work with OS X 10.8.2 clients and followed your configuration in the picture but it fails.

Do you have any other payloads configured on this? e.g.- "AD Certificate" payload

In my configuration I have;
Network payload with configuration exactly like yours
Certificate payload with AD certsrv CA certificate chain and wi-fi cert

I need to find out what i'm missing?

Thanks
Thusitha


Forum|alt.badge.img+14
  • Author
  • Contributor
  • March 13, 2013

Hey Thusitha, I dont have anything else configured in that profile. I would make sure to take a look at the google page that bbergstein mentioned above. Modifying our cert template is what really allowed us to make this work. Also make sure you are deploying the profile at a Computer Level.