<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi, I've tried searching for this already, but can anyone point me in the direction of any guides for deploying an SSID within HMNG that uses certificate based authentication? in Aerohive Migrated Content</title>
    <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86324#M11035</link>
    <description>&lt;P&gt;Hi Sam, Many thanks for responding and for the guidance. I've set this up and have it working with a Local Database. When I join the network, I'm prompted for a username &amp;amp; password, then have to accept/install the certificate. Once done, I'm connected and everything works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, whilst this may turn out to be a workable solution for us, I'm wondering if it's possible to make this even easier for our users. Ideally, I'd like the SSID to use 802.1X (as per your suggested configuration), but when a user taps on the SSID to join the network, all the AP needs to authenticate is a certificate that we'll pre-deploy on the mobile/cell (iPhone) using our MDM solution.  So, basically the same as you've detailed above, but without requiring a username &amp;amp; password. Is that possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks, Tony&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2019 03:10:44 GMT</pubDate>
    <dc:creator>tony_mitchell</dc:creator>
    <dc:date>2019-06-21T03:10:44Z</dc:date>
    <item>
      <title>Hi, I've tried searching for this already, but can anyone point me in the direction of any guides for deploying an SSID within HMNG that uses certificate based authentication?</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86322#M11033</link>
      <description>&lt;P&gt;In particular, I'm looking for a use case where I want to use a generic certificate across multiple mobile devices which enables them to seamlessly connect to a WiFi network? I don't want to generate or require each unique user to have a certificate, just the device. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 15:57:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86322#M11033</guid>
      <dc:creator>tony_mitchell</dc:creator>
      <dc:date>2019-06-20T15:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I've tried searching for this already, but can anyone point me in the direction of any guides for deploying an SSID within HMNG that uses certificate based authentication?</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86323#M11034</link>
      <description>&lt;P&gt;You'll want to follow this guide for the most part, to set up a Radius server on an AP (which can be using an external AD you've already set up, or an internal user database hosted in the HiveManager): &lt;A href="https://thehivecommunity.aerohive.com/s/article/Radius-SSID-in-NG" alt="https://thehivecommunity.aerohive.com/s/article/Radius-SSID-in-NG" target="_blank"&gt;https://thehivecommunity.aerohive.com/s/article/Radius-SSID-in-NG&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you reach the part where you are configuring the AAA Server Profile, you'll want to open the Security Options tab:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="388e6a730c0b48d28cc3a18cb168ab18_0690c000008P7aqAAC.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4432i6FE7390646B1DEA1/image-size/large?v=v2&amp;amp;px=999" role="button" title="388e6a730c0b48d28cc3a18cb168ab18_0690c000008P7aqAAC.png" alt="388e6a730c0b48d28cc3a18cb168ab18_0690c000008P7aqAAC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here you can upload the certificate that the clients need to match, and set the Radius server to check for the certificate during authentication (TLS authentication). &lt;/P&gt;&lt;P&gt;&lt;IMG src="sfdc://0690c000008P7bKAAS" alt="21" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 21:22:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86323#M11034</guid>
      <dc:creator>samantha_lynn</dc:creator>
      <dc:date>2019-06-20T21:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I've tried searching for this already, but can anyone point me in the direction of any guides for deploying an SSID within HMNG that uses certificate based authentication?</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86324#M11035</link>
      <description>&lt;P&gt;Hi Sam, Many thanks for responding and for the guidance. I've set this up and have it working with a Local Database. When I join the network, I'm prompted for a username &amp;amp; password, then have to accept/install the certificate. Once done, I'm connected and everything works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, whilst this may turn out to be a workable solution for us, I'm wondering if it's possible to make this even easier for our users. Ideally, I'd like the SSID to use 802.1X (as per your suggested configuration), but when a user taps on the SSID to join the network, all the AP needs to authenticate is a certificate that we'll pre-deploy on the mobile/cell (iPhone) using our MDM solution.  So, basically the same as you've detailed above, but without requiring a username &amp;amp; password. Is that possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks, Tony&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 03:10:44 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86324#M11035</guid>
      <dc:creator>tony_mitchell</dc:creator>
      <dc:date>2019-06-21T03:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I've tried searching for this already, but can anyone point me in the direction of any guides for deploying an SSID within HMNG that uses certificate based authentication?</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86325#M11036</link>
      <description>&lt;P&gt;It is possible to have a certificate only authentication, but for that to work each client would need their own unique certificate, rather than the same certificate installed on each device. Does that sound like something you'd want to pursue?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 23:44:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/hi-i-ve-tried-searching-for-this-already-but-can-anyone-point-me/m-p/86325#M11036</guid>
      <dc:creator>samantha_lynn</dc:creator>
      <dc:date>2019-06-21T23:44:23Z</dc:date>
    </item>
  </channel>
</rss>

