<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Android 11 Update - Server Cert Validation Error and Solutions in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35847#M1585</link>
    <description>&lt;P&gt;Adam,&lt;/P&gt;&lt;P&gt;With this option you can present a public certificate to unknown devices/users and a corporate certificate to corporate devices.&lt;/P&gt;&lt;P&gt;From my point of view I have a solution to my own use cases.&lt;/P&gt;&lt;P&gt;I’m installing this version and give feedback on it.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
    <pubDate>Thu, 24 Dec 2020 00:43:00 GMT</pubDate>
    <dc:creator>Miguel-Angel_RO</dc:creator>
    <dc:date>2020-12-24T00:43:00Z</dc:date>
    <item>
      <title>Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35842#M1580</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;With the new Android 11 update being pushed out now.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"In December 2020, the planned Android 11 QPR1 security update will disable the ability to select “&lt;STRONG&gt;Do not validate&lt;/STRONG&gt;” for the&amp;nbsp;&lt;STRONG&gt;“CA Certificate&lt;/STRONG&gt;” dropdown in network settings for a given SSID"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;While the change itself is a minor one,&lt;STRONG&gt;&amp;nbsp;it will have a disproportionately far-reaching impact&lt;/STRONG&gt;. Many organizations use this setting to avoid implementing proper EAP server certificate validation due to the perceived difficulty of configuring x.509 digital certificate authentication.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Come December, Androids configured with this workaround will find their Wi-Fi services interrupted. Organizations need to address this issue now to prevent chaos as updates gradually roll out to Android devices throughout the month.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Managed devices are easy to configure and enroll, but most Android devices on a network are (understandably) BYOD. That means that, at some point in the process of configuration, the end user has to be involved. There are a myriad of different types of Androids and, despite their common operating system, they rarely all follow the same configuration blueprint. "&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some other Vendors allows for installation of a Certificate to Android devices using their NAC solutions.&amp;nbsp;Will Extreme have a solution for this or is it&amp;nbsp;something that we would need to look at some 3rd party?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 21:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35842#M1580</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2020-12-08T21:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35843#M1581</link>
      <description>&lt;P&gt;Hi Andre,&lt;/P&gt;&lt;P&gt;You should open a ticket at GTAC as a question for this specific topic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my perspective we’ll have to reshuffle the way we configure the services for BYOD devices.&lt;/P&gt;&lt;P&gt;Whatever solution we use, there will always be some action to be taken by the end users if authenticate BYOD on 802.1X enabled SSIDs.&lt;/P&gt;&lt;P&gt;The tricky part, is not the 802.1X, it is the user…&lt;/P&gt;&lt;P&gt;In big companies, you have all the profiles and some aren’t very comfortable with IT stuff.&lt;/P&gt;&lt;P&gt;This was the reason for the “Do not Validate” option. If this option is gone, we have to rethink the way we provide the service for the BYOD. All the on-boarding solutions I’ve seen are too complex for the lambda user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, if you have some feedback from GTAC please share it.&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 23:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35843#M1581</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-12-08T23:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35844#M1582</link>
      <description>&lt;P&gt;Ask your local engineer for information about Extreme&amp;nbsp;A3. And don’t worry about some indications that it is Cloud-based NAC. Installation is local and connection to CloudIQ is not required.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 11:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35844#M1582</guid>
      <dc:creator>Adam_Minowski</dc:creator>
      <dc:date>2020-12-19T11:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35845#M1583</link>
      <description>&lt;P&gt;Andre,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You lucky guy &lt;span class="lia-inline-image-display-wrapper" image-alt="aac9684f123f40bd82f95e1963b905d9_1f609.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5882i573BEDE86B850859/image-size/large?v=v2&amp;amp;px=999" role="button" title="aac9684f123f40bd82f95e1963b905d9_1f609.png" alt="aac9684f123f40bd82f95e1963b905d9_1f609.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="aac9684f123f40bd82f95e1963b905d9_bf396d11-47f0-4990-9b04-0c0b5701e2f5.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1251iEEB87FE2B884F171/image-size/large?v=v2&amp;amp;px=999" role="button" title="aac9684f123f40bd82f95e1963b905d9_bf396d11-47f0-4990-9b04-0c0b5701e2f5.png" alt="aac9684f123f40bd82f95e1963b905d9_bf396d11-47f0-4990-9b04-0c0b5701e2f5.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 21:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35845#M1583</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-12-23T21:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35846#M1584</link>
      <description>&lt;P&gt;Miguel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This one doesn’t relate to the topic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; The described feature relates to&amp;nbsp;server side. It does not&amp;nbsp;address&amp;nbsp;a problem with the client. Client still needs&amp;nbsp;to accept unknown (not validated)&amp;nbsp;NAC certificate or use “don’t validate” option.&lt;/P&gt;&lt;P&gt;In order for server cert to be accepted by the client you have to use server cert, signed by known CA (such as Versigin, GoDaddy etc...). If your organization is&amp;nbsp;using internal CA, or any kind self-signed one, which is usually&amp;nbsp;the case, then you will get&amp;nbsp;the same problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to solve it, you should&amp;nbsp;at least have&amp;nbsp;a&amp;nbsp;possibility to push local CA public key to the client device (eg. to root certificates store). In more sophisticated scenarios you can also generate client cert and key on behalf of client and push it. It can be done only with special features on NAC side - because the NAC have to be “a broker” between CA and client, and should provide technique for delivering certs to client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 22:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35846#M1584</guid>
      <dc:creator>Adam_Minowski</dc:creator>
      <dc:date>2020-12-23T22:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35847#M1585</link>
      <description>&lt;P&gt;Adam,&lt;/P&gt;&lt;P&gt;With this option you can present a public certificate to unknown devices/users and a corporate certificate to corporate devices.&lt;/P&gt;&lt;P&gt;From my point of view I have a solution to my own use cases.&lt;/P&gt;&lt;P&gt;I’m installing this version and give feedback on it.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 00:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35847#M1585</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-12-24T00:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35848#M1586</link>
      <description>&lt;P&gt;That is true, but still for “public” service you need to have valid/commercial certificate signed by well-known authority. This is something worth mentioning to avoid surprises &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andre in his original question asked if Extreme can provide him a solution with certificate onboarding/provisioning. YES&amp;nbsp;we&amp;nbsp;can.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 00:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35848#M1586</guid>
      <dc:creator>Adam_Minowski</dc:creator>
      <dc:date>2020-12-24T00:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35849#M1587</link>
      <description>&lt;P&gt;That is true, but still for “public” service you need to have valid/commercial certificate signed by well-known authority. This is something worth mentioning to avoid surprises &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;	&amp;nbsp;&lt;/P&gt;	&lt;P&gt;Andre in his original question asked if Extreme can provide him a solution with certificate onboarding/provisioning. YES&amp;nbsp;we&amp;nbsp;can.&lt;/P&gt;	&lt;P&gt;&lt;BR /&gt;Indeed, I use a public certificate for a public service to avoid those onboarding issues but I need to use a corporate certificate for the corporate devices. This option is matching my use cases but not fully matching the use case of Andre.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 00:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35849#M1587</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-12-24T00:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: Android 11 Update - Server Cert Validation Error and Solutions</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35850#M1588</link>
      <description>&lt;P&gt;All, I am getting same issue. Users having Google pixel phone report this issue so far.&lt;/P&gt;&lt;P&gt;Is there any option in extreme cloudIQ to fix the issue ? any workaround ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 22:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/android-11-update-server-cert-validation-error-and-solutions/m-p/35850#M1588</guid>
      <dc:creator>ramesh_pandey</dc:creator>
      <dc:date>2021-03-31T22:05:00Z</dc:date>
    </item>
  </channel>
</rss>

