802.1x AD login

tcandela
Valued Contributor II

I have some iMacs that will need Wi-Fi AD login (no ethernet ports nearby). How do I go about this?

do i create a configuration profile --> network --> wi-fi

what other payloads will need to be configured ? will this just be 1 config profile?

6 REPLIES 6

duffcalifornia
Contributor

If you have a certificate based wifi network, then yes, you'd create a configuration profile. All you would need would be the specific certificates uploaded (you can pull them from Keychain Access) and the network payload to be configured for your SSID.

alexjdale
Valued Contributor III

The answer really will depend on your WiFi authentication setup.

We have system-level authentication, which means the system itself authenticates with wireless automatically on startup, so users just log in since the network is available. Our config profile includes the network setup and an AD certificate config for the system.

You can also set up a profile that uses the user's credentials to authenticate with wireless, if your network supports that.

tcandela
Valued Contributor II

I have it as level to apply profile as a computer level profile

what is that 'USE AS A LOGIN WINDOW CONFIGURATION' checkbox in the NETWORKS payload? do i Check that ?

do i check 'auto join' ?

so far i have the network payload with
- wifi
- ssid
- auto join ???
- wpa2 enterprise
- use as a login window authentication ??
- protocols = - trust =

esembly4
New Contributor III

You'll need to insert your certs in the certificates tab
9853f97aa191411ea2b47cb976a4c751

Then configure your network tab like this
7838b14259844d70919c7da71b168319

That should give the users the ability to authenticate the computer to the wifi and then login.

tcandela
Valued Contributor II

@uaesembly what about the TRUST tab? anything get set in there ?

for the PROTOCOLS tab, only PEAP gets checked? no other values get entered such as username/password etc. ?

ooshnoo
Valued Contributor

The protocols you use will depend on what the network is configure for. Ask your network admins