Skip to main content
Question

Using 802.1x EAP-TLS user certificates with Casper

  • July 15, 2014
  • 3 replies
  • 9 views

Forum|alt.badge.img+18

Good Morning, all.

I tried to thoroughly read all of the threads regarding PKI, but I am having a hard time dredging up an answer.
Our enterprise wireless access points use user certificates generated from a Microsoft Certificate Services portal to connect employees to our wireless network. It's currently a very manual process, and I would like to find some way to automate (partially automate?) the process. I found article: https://jamfnation.jamfsoftware.com/article.html?id=209 that explains how to request device certificates from the JSS using configuration profiles, but is there a way to request user-level certificates, also? Sorry if I was unclear in any way.

Thanks,
Bruce

3 replies

Forum|alt.badge.img+13
  • Valued Contributor
  • July 15, 2014

Yes; the Config Profile would be user-level. Set up the SCEP payload to pull their ID cert (based on username I'm guessing), and then set up the WiFi payload to use the SCEP-provided cert for WPA2 Enterprise w/TLS.


Forum|alt.badge.img+18
  • Author
  • Valued Contributor
  • July 15, 2014

I guess I need to convince the certificate management folks to begin using SCEP...


Forum|alt.badge.img+13
  • Valued Contributor
  • July 15, 2014

Indeed; you'll need your cert admin to set this up for you, but I can't see a downside.