EAP-TLS option missing from Join Network screen

guidotti
Contributor II

Hello, all.

I am having an odd issue that I've only seen once before.
When I try to connect a MacBook Air to our enterprise WiFi (WPA2 Enterprise, EAP-TLS with user certificate), it only shows the username and password prompt. There is no mode dropdown picker box to switch between Automatic (PEAP) and EAP (TLS). Has anyone ever seen that before? I tried: change to different profile, repair keychain, delete and recreate keychain, and even a reformat from recovery mode. Still I have the issue. I will attach a screenshot from a working machine and the one from this machine. It is a MacBookAir6,1, and I've tried this on 10.9.3, 10.9.4, and 10.9.5. The other device that is working is identical hardware that was bought at the same time. Help, it's driving me nuts!
external image link
external image link

1 ACCEPTED SOLUTION

guidotti
Contributor II

Thanks for the input, guys. It turns out that the user certificate that our PKI guys sent me was created with the wrong template. Once I had them recreate the certificate, I imported it into the keychain and the option for EAP-TLS magically appeared.

View solution in original post

4 REPLIES 4

mostlikelee
Contributor

I've only seen that behavior when the Network configuration profile deployed has "Use as a Login Window configuration" unchecked.

guidotti
Contributor II

That's interesting since this is right after a fresh wipe with no configuration profiles deployed. The device is not even enrolled in the JSS at this point - fresh out of the box, so to speak.

colonelpanic
Contributor

You aren't going crazy, I have seen the same behavior as well, but not often enough to dig into the cause.

guidotti
Contributor II

Thanks for the input, guys. It turns out that the user certificate that our PKI guys sent me was created with the wrong template. Once I had them recreate the certificate, I imported it into the keychain and the option for EAP-TLS magically appeared.