meta data for this page
  •  

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
network:wifi:wpae [2023/06/21 14:02] niziaknetwork:wifi:wpae [2023/10/23 11:14] (current) niziak
Line 1: Line 1:
 ====== WiFi WPA Enterprise ====== ====== WiFi WPA Enterprise ======
 +
 +===== Win 11 =====
 +
 +Windows 11 22H2 not connecting to WPA Enterprise
 +
 +  - Open Registry Editor
 +  - Navigate to ''HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RasMan\PPP\EAP\13''
 +  - Create ''DWORD'' key ''TlsVersion'' value ''FC0''
 +
 +''TlsVersion'' coding (values cane be OR-ed):
 +  - 0000 1100 0000 = 0x0C0 TLS1.0
 +  - 0011 0000 0000 = 0x300 TLS1.1
 +  - 1100 0000 0000 = 0xC00 TLS1.2
  
 ===== Android 11+ Devices ===== ===== Android 11+ Devices =====
Line 38: Line 51:
  
 TODO TODO
 +
  
 Android:  Android: 
Line 44: Line 58:
 [[https://learn.microsoft.com/pl-pl/mem/intune/configuration/wi-fi-settings-android-enterprise]] [[https://learn.microsoft.com/pl-pl/mem/intune/configuration/wi-fi-settings-android-enterprise]]
  
 +[[https://community.ui.com/questions/what-domain-for-android-when-setting-up-wpa2-enterprise-w-built-in-radius/4efa22a5-c909-465b-9755-a8507e34b08a#answer/3a14eb34-5ead-47ed-9472-910752c7ee50]]
 +
 +
 +
 +[[https://community.ui.com/questions/UDM-Radius-WPA-Enterprise-Android-11/10e1ef71-a0e5-4b83-885d-80deccbdef25]]
 +<code>
 +I don't disagree, but bottom line is that 11 will never connect without a trusted CA root (and all intermediates in the chain, if there are any, above the certificate your RADIUS server is presenting) physically installed to the phone. Just how it is. 
 +</code>
 +
 +Starting with Android 11 QPR1, you must enter the domain for server certification validation in order to successfully connect.
  
  
Line 55: Line 79:
 Add both certs to client ? how to add intermediate ca ? Add both certs to client ? how to add intermediate ca ?
  
 +New CA are added to ''User store'' only. There is no option without root right to move it to ''System store''