Skip to main content
Solved

EAP-TLS option missing from Join Network screen

  • September 26, 2014
  • 4 replies
  • 43 views

Forum|alt.badge.img+18

Hello, all.

I am having an odd issue that I've only seen once before.
When I try to connect a MacBook Air to our enterprise WiFi (WPA2 Enterprise, EAP-TLS with user certificate), it only shows the username and password prompt. There is no mode dropdown picker box to switch between Automatic (PEAP) and EAP (TLS). Has anyone ever seen that before? I tried: change to different profile, repair keychain, delete and recreate keychain, and even a reformat from recovery mode. Still I have the issue. I will attach a screenshot from a working machine and the one from this machine. It is a MacBookAir6,1, and I've tried this on 10.9.3, 10.9.4, and 10.9.5. The other device that is working is identical hardware that was bought at the same time. Help, it's driving me nuts!
external image link
external image link

Best answer by guidotti

Thanks for the input, guys. It turns out that the user certificate that our PKI guys sent me was created with the wrong template. Once I had them recreate the certificate, I imported it into the keychain and the option for EAP-TLS magically appeared.

4 replies

Forum|alt.badge.img+9
  • Contributor
  • September 26, 2014

I've only seen that behavior when the Network configuration profile deployed has "Use as a Login Window configuration" unchecked.


Forum|alt.badge.img+18
  • Author
  • Valued Contributor
  • September 29, 2014

That's interesting since this is right after a fresh wipe with no configuration profiles deployed. The device is not even enrolled in the JSS at this point - fresh out of the box, so to speak.


Forum|alt.badge.img+7
  • Contributor
  • September 30, 2014

You aren't going crazy, I have seen the same behavior as well, but not often enough to dig into the cause.


Forum|alt.badge.img+18
  • Author
  • Valued Contributor
  • Answer
  • October 1, 2014

Thanks for the input, guys. It turns out that the user certificate that our PKI guys sent me was created with the wrong template. Once I had them recreate the certificate, I imported it into the keychain and the option for EAP-TLS magically appeared.