HI All,
I know this has been mentioned several times but after trying all the suggestions it still isn't working
10.10.4 clients
Currently I can get machine based certs from AD fine using profile manager
When I add a network payload configured :
Network Interface : Ethernet
PROTOCOLS
EAP type: TTLS - PEAP, this is taken from when I manually connect as a user
Username and PW blank, although I have tried many things including: %AD_ComputerID%, host/ Machine MacComputer(AD Template) all in the UN field and leaving PW blank
Identity Certificate : AD Certificate pre configured and verified working
Inner Auth : MSCHAPv2
Outer Identity Blank
TRUST
Installed every possible certificate I can get my hands on including, Domain, Root, 3 radius servers
trusted Server Certificate names: I added each of the certificate names here separately, then added all of them together, left it blank.
Hopefully someone has some ideas on how I can get this working. I have confirmed with our network team that I should be able to authenticate using the AD Machine based certificate.
Thanks in Advance
EDIT: I cannot find where to turn on logging for this either to check what is happening......
EDIT2: So..... a little more trial and error, I have managed to get a little further when it is now prompting to use a profile, Is there any way to automate this so there is no user interaction?
When I select the 802.1x profile it then prompts : Select the certificate or enter username and password for this 802.1x network, I select certificate (any way to automate this as well?)
it then prompts for machine password???