{"id":37065,"date":"2019-10-31T22:15:33","date_gmt":"2019-10-31T19:15:33","guid":{"rendered":"https:\/\/prohoster.info\/blog\/wifi-enterprise-freeradius-freeipa-ubiquiti\/"},"modified":"2019-10-31T22:15:33","modified_gmt":"2019-10-31T19:15:33","slug":"wifi-enterprise-freeradius-freeipa-ubiquiti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/wifi-enterprise-freeradius-freeipa-ubiquiti","title":{"rendered":"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/4c045a0710e5eb14b73359afad484c3d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSome examples of organizing corporate WiFi have already been described. Here, I will explain how I implemented a similar solution and the issues I faced when connecting different devices. We will use the existing LDAP with established users, set up FreeRadius, and configure WPA2-Enterprise on the Ubnt controller. It seems straightforward. Let's see\u2026<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>A bit about EAP methods<\/h2>\n<p>\nBefore starting the task, we need to determine which authentication method we will use in our solution.<\/p>\n<p><b>From Wikipedia:<\/b><\/p>\n<blockquote><p>EAP is an authentication framework commonly used in wireless networks and point-to-point connections. The format was first described in RFC 3748 and updated in RFC 5247.<br \/>\nEAP is used to select the authentication method, transmit keys, and process these keys through modules called EAP methods. There are many EAP methods, both defined together with EAP and released by individual manufacturers. EAP does not specify the link layer; it only defines the message format. Each protocol using EAP has its own EAP message encapsulation protocol. <\/p><\/blockquote>\n<p>\n<b>The methods themselves:<\/b><\/p>\n<ul>\n<li>LEAP is a proprietary protocol developed by CISCO. Vulnerabilities have been found. It is currently not recommended for use. <\/li>\n<li> EAP-TLS is well supported among wireless connection vendors. It is a secure protocol as it is the successor to SSL standards. Client configuration is quite complex. A client certificate is required in addition to a password. It is supported in many systems. <\/li>\n<li> EAP-TTLS is widely supported in many systems and offers good security by using PKI certificates only on the authentication server. <\/li>\n<li> EAP-MD5 is another open standard. It offers minimal security and is vulnerable; it does not support mutual authentication or key generation. <\/li>\n<li> EAP-IKEv2 is based on the Internet Key Exchange Protocol version 2. It provides mutual authentication and establishes a session key between the client and the server. <\/li>\n<li> PEAP is a joint solution from CISCO, Microsoft, and RSA Security as an open standard. It is widely available in products and provides very good security. It is similar to EAP-TTLS, requiring only a certificate on the server side. <\/li>\n<li> PEAPv0\/EAP-MSCHAPv2 \u2014 after EAP-TLS, this is the second widely used standard in the world. It utilizes client-server interaction in Microsoft, Cisco, Apple, and Linux. <\/li>\n<li> PEAPv1\/EAP-GTC \u2014 created by Cisco as an alternative to PEAPv0\/EAP-MSCHAPv2. It does not protect authentication data in any case. Not supported in Windows OS. <\/li>\n<li> EAP-FAST \u2014 a method developed by Cisco to address the shortcomings of LEAP. It uses Protected Access Credential (PAC). Fully underdeveloped. <\/li>\n<\/ul>\n<p>\nAmong all this variety, the choice is still limited. The authentication method required good security, support on all devices (Windows 10, macOS, Linux, Android, iOS), and, essentially, the simpler, the better. Therefore, the choice fell on EAP-TTLS in conjunction with the PAP protocol. <br \/>\nA question may arise \u2014 Why use PAP? doesn\u2019t it transmit passwords in clear text? <\/p>\n<p>Yes, that\u2019s right. Communication between FreeRadius and FreeIPA will proceed this way. In debug mode, you can track how the username and password are sent. And let them be sent, only you have access to the FreeRadius server.<\/p>\n<p>You can read more about how EAP-TTLS works. <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.bmstu.wiki\/EAP-TTLS_(Tunneled_Transport_Layer_Security)\">here<br \/>\n<\/a><\/noindex><\/p>\n<h2>FreeRADIUS<\/h2>\n<p>\nWe will set up FreeRadius on CentOS 7.6. There\u2019s nothing complicated here, we\u2019ll install it in the usual way.<\/p>\n<pre><code class=\"bash\">yum install freeradius freeradius-utils freeradius-ldap -y<\/code><\/pre>\n<p>\n<i>Version 3.0.13 is installed from the packages. You can get the latest version at <noindex><a rel=\"nofollow\" href=\"https:\/\/freeradius.org\/\">https:\/\/freeradius.org\/<\/a><\/noindex><\/i><\/p>\n<p>After this, FreeRadius will already be working. You can uncomment the line in \/etc\/raddb\/users:<\/p>\n<pre><code class=\"bash\">steve   Cleartext-Password := \"testing\"<\/code><\/pre>\n<p>\nRun the server in debug mode.<\/p>\n<pre><code class=\"bash\">freeradius -X<\/code><\/pre>\n<p>\nAnd let\u2019s do a test connection from localhost.<\/p>\n<pre><code class=\"bash\">radtest steve testing 127.0.0.1 1812 testing123<\/code><\/pre>\n<p>\nWe received the response. <i>Received Access-Accept Id 115 from 127.0.0.1:1812 to 127.0.0.1:56081 length 20.<\/i>, so everything is good. Let's move on.<\/p>\n<p>We connect the module. <i><b>ldap<\/b><\/i>.<\/p>\n<pre><code class=\"bash\">ln -s \/etc\/raddb\/mods-available\/ldap \/etc\/raddb\/mods-enabled\/ldap<\/code><\/pre>\n<p>\nAnd we will change it immediately. We need FreeRadius to be able to connect to FreeIPA.<\/p>\n<p><b class=\"spoiler_title\">mods-enabled\/ldap<\/b><\/p>\n<pre><code class=\"bash\">ldap {\nserver=\"ldap:\/\/ldap.server.com\"\nport=636\nstart_tls=yes\nidentity=\"uid=admin,cn=users,dc=server,dc=com\"\npassword=**********\nbase_dn=\"cn=users,dc=server,dc=com\"\nset_auth_type=yes\n...\nuser {\nbase_dn=\"${..base_dn}\"\nfilter=\"(uid=%{%{Stripped-User-Name}:-%{User-Name}})\"\n}\n...<\/code><\/pre>\n<p>We restart the radius server and check the synchronization of LDAP users:<\/p>\n<pre><code class=\"bash\">radtest user_ldap password_ldap localhost 1812 testing123<\/code><\/pre>\n<p>\nWe edit eap in <i><b>mods-enabled\/eap<\/b><\/i><br \/>\nHere we will add two instances of eap. They will differ only in certificates and keys. I will explain further down why it is done this way.<\/p>\n<p><b class=\"spoiler_title\">mods-enabled\/eap<\/b><\/p>\n<pre><code class=\"bash\">eap eap-client {                                                                                                                                                                                                                           default_eap_type = ttls                                                                                                                                                                                                                 timer_expire = 60                                                                                                                                                                                                                       ignore_unknown_eap_types = no                                                                                                                                                                                                          cisco_accounting_username_bug = no                                                                                                                                                                                                      max_sessions = ${max_requests}\n           tls-config tls-common {\n           private_key_file = ${certdir}\/fisrt.key\n           certificate_file = ${certdir}\/first.crt\n           dh_file = ${certdir}\/dh\n           ca_path = ${cadir}\n           cipher_list = \"HIGH\"\n           cipher_server_preference = no\n           ecdh_curve = \"prime256v1\"\n           check_crl = no\n           }\n                                                                                                                                                                                                                                                                                                                                                                                                                                                 \n           ttls {\n           tls = tls-common\n           default_eap_type = md5\n           copy_request_to_tunnel = no\n           use_tunneled_reply = yes\n           virtual_server = \"inner-tunnel\"\n           }\n}\neap eap-guest {\ndefault_eap_type = ttls                                                                                                                                                                                                                 timer_expire = 60                                                                                                                                                                                                                       ignore_unknown_eap_types = no                                                                                                                                                                                                          cisco_accounting_username_bug = no                                                                                                                                                                                                      max_sessions = ${max_requests}\n           tls-config tls-common {\n           private_key_passwotd=blablabla\n           private_key_file = ${certdir}\/server.key\n           certificate_file = ${certdir}\/server.crt\n           dh_file = ${certdir}\/dh\n           ca_path = ${cadir}\n           cipher_list = \"HIGH\"\n           cipher_server_preference = no\n           ecdh_curve = \"prime256v1\"\n           check_crl = no\n           }\n                                                                                                                                                                                                                                                                                                                                                                                                                                                 \n           ttls {\n           tls = tls-common\n           default_eap_type = md5\n           copy_request_to_tunnel = no\n           use_tunneled_reply = yes\n           virtual_server = \"inner-tunnel\"\n           }\n}<\/code><\/pre>\n<p>Next, we edit <i><b>site-enabled\/default<\/b><\/i>. We are interested in the authorize and authenticate sections.<\/p>\n<p><b class=\"spoiler_title\">site-enabled\/default<\/b><\/p>\n<pre><code class=\"bash\">authorize {\n  filter_username\n  preprocess\n  if (&amp;User-Name == \"guest\") {\n   eap-guest {\n       ok = return\n   }\n  }\n  elsif (&amp;User-Name == \"client\") {\n    eap-client {\n       ok = return \n    }\n  }\n  else {\n    eap-guest {\n       ok = return\n    }\n  }\n  ldap\n  if ((ok || updated) &amp;&amp; User-Password) {\n    update {\n        control:Auth-Type := ldap\n    }\n  }\n  expiration\n  logintime\n  pap\n}\n\nauthenticate {\n  Auth-Type LDAP {\n    ldap\n  }\n  Auth-Type eap-guest {\n    eap-guest\n  }\n  Auth-Type eap-client {\n    eap-client\n  }\n  pap\n}<\/code><\/pre>\n<p>In the authorize section, we remove all unnecessary modules. We keep only ldap. We also add a client check using the username. This is why we added two instances of eap above.<\/p>\n<p><b class=\"spoiler_title\">Multi EAP<\/b>The thing is, when connecting certain devices, we will use system certificates and specify the domain. We have a certificate and key from a trusted certificate authority. Personally, I believe this connection procedure is easier than deploying self-signed certificates to each device. However, we cannot avoid self-signed certificates altogether. Samsung devices and Android versions &lt;= 6 do not support using system certificates. Therefore, we create a separate instance of eap-guest with self-signed certificates for them. For all other devices, we will use eap-client with a trusted certificate. The User-Name is determined by the Anonymous field when connecting the device. Only 3 values are allowed: Guest, Client, and an empty field. All others are discarded. This is configured in the policies. I will provide an example a bit later.<\/p>\n<p>We will edit the authorize and authenticate sections in <i><b>site-enabled\/inner-tunnel<\/b><\/i><\/p>\n<p><b class=\"spoiler_title\">site-enabled\/inner-tunnel<\/b><\/p>\n<pre><code class=\"bash\">authorize {\n  filter_username\n  filter_inner_identity\n  update control {\n   &amp;Proxy-To-Realm := LOCAL\n  }\n  ldap\n  if ((ok || updated) &amp;&amp; User-Password) {\n    update {\n        control:Auth-Type := ldap\n    }\n  }\n  expiration\n  digest\n  logintime\n  pap\n}\n\nauthenticate {\n  Auth-Type eap-guest {\n    eap-guest\n  }\n  Auth-Type eap-client {\n    eap-client\n  }\n  Auth-Type PAP {\n    pap\n  }\n  ldap\n}<\/code><\/pre>\n<p>Next, we need to specify in the policies which usernames can be used for anonymous login. We edit <b><i>policy.d\/filter<\/i><\/b>.<\/p>\n<p>We need to find lines resembling this:<\/p>\n<pre><code class=\"bash\">if (&amp;outer.request:User-Name !~ \/^(anon|@)\") {\n  update request {\n    Module-Failure-Message = \"User-Name is not anonymized\"\n  }\n  reject\n}<\/code><\/pre>\n<p>\nAnd below, in elsif, add the required values:<\/p>\n<pre><code class=\"bash\">elsif (&amp;outer.request:User-Name !~ \/^(guest|client|@)\") {\n  update request {\n    Module-Failure-Message = \"User-Name is not anonymized\"\n  }\n  reject\n}<\/code><\/pre>\n<p>\nNow we need to navigate to the directory <b><i>certs<\/i><\/b>. Here, we need to place the key and certificate from the trusted certificate authority that we already have, and we need to generate self-signed certificates for eap-guest.<\/p>\n<p>Change parameters in the file <b><i>ca.cnf<\/i><\/b>.<\/p>\n<p><b class=\"spoiler_title\">ca.cnf<\/b><\/p>\n<pre><code class=\"bash\">\n...\ndefault_days = 3650\ndefault_md = sha256\n...\ninput_password = blablabla\noutput_password = blablabla\n...\ncountryName = RU\nstateOrProvinceNmae = State\nlocalityNmae = City\norganizationName = NONAME\nemailAddress = admin@admin.ru\ncommonName = \"CA FreeRadius\"<\/code><\/pre>\n<p>We write the same values in the file <b><i><i>server.cnf<\/i><\/i><\/b>. We only change <br \/>\n<b>commonName<\/b>:<\/p>\n<p><b class=\"spoiler_title\">server.cnf<\/b><\/p>\n<pre><code class=\"bash\">\n...\ndefault_days = 3650\ndefault_md = sha256\n...\ninput_password = blablabla\noutput_password = blablabla\n...\ncountryName = RU\nstateOrProvinceNmae = State\nlocalityNmae = City\norganizationName = NONAME\nemailAddress = admin@admin.ru\ncommonName = \"Server Certificate FreeRadius\"<\/code><\/pre>\n<p>Create:<\/p>\n<pre><code class=\"bash\">make<\/code><\/pre>\n<p>\nDone. The obtained <b><i>server.crt<\/i><\/b> and <b><i>server.key<\/i><\/b> are already listed above in eap-guest.<\/p>\n<p>And finally, we will add our access points to the file <b><i>client.conf<\/i><\/b>. I have 7 of them. To avoid adding each point separately, we will only specify the network they are in (my access points are in a separate VLAN).<\/p>\n<pre><code class=\"bash\">client APs {\nipaddr = 192.168.100.0\/24\npassword = password_AP\n}<\/code><\/pre>\n<p><\/p>\n<h2>Ubiquiti controller<\/h2>\n<p>\nOn the controller, we set up a separate network. Let's use 192.168.2.0\/24<br \/>\nGo to settings -&gt; profile. Create a new one:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/57d97f7ef2db1a62633aa16131435065.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSpecify the address and port of the radius server along with the password we set in the file <b><i>clients.conf<\/i><\/b>:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/edab8e5ef03897c88bb45b2912e577ec.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nCreate a new wireless network name. Select WPA-EAP (Enterprise) as the authentication method and specify the created radius profile:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/9dc918b734cac3d7382db796feb6b7a2.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSave everything, apply, and move on.<\/p>\n<h2>Client setup<\/h2>\n<p>\nLet\u2019s start with the most challenging part!<\/p>\n<h3>Windows 10<\/h3>\n<p>\nThe issue is that Windows still cannot connect to corporate WiFi using domain authentication. Therefore, we need to manually add our certificate to the trusted certificate store. You can use either a self-signed certificate or one from a certification center. I will use the latter. <\/p>\n<p>Next, you need to create a new connection. For this, go to Network &amp; Internet settings -&gt; Network and Sharing Center -&gt; Set up a new connection or network:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/406e515cff889ea70e226116f1dc0521.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/f88e592920e43d42cc7fed34423f09ea.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/1d7c045e02eb8e3b14016aacfa00da4c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nManually specify the network name and change the security type. Then click on <i>change connection settings<\/i> and on the Security tab, select network authentication \u2014 EAP-TTLS.<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/7e736b4cffd6dca5fdd9df70cedd7988.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/6c328ff8b4a434ed488c46b594aa5108.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/d4a3d2883088a06592addae770a12a16.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nGo to settings, specify authentication privacy \u2014 <b>client<\/b>. Choose the added certificate as the trusted certificate authority, check the box \"Do not prompt user if server authorization fails\" and select the authentication method \u2014 unencrypted password (PAP).<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/eb4897493f805f0d8869c22a1b706dec.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNext, go to the advanced settings, check the box for \"Specify authentication mode.\" Select the option \"User authentication\" and click on <i>save credentials<\/i>. Here you will need to enter username_ldap and password_ldap<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/469bb4337e4e601a80de1021a48bc101.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/999dc6c41a69b22c8de2b49398c9a613.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/75347f2f7140cac58a181a325ab0f3ad.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe save everything, apply, and close. You can now connect to the new network.<\/p>\n<h3>Linux<\/h3>\n<p>\nI tested it on Ubuntu 18.04, 18.10, Fedora 29, 30.<\/p>\n<p>First, we need to download the certificate. I couldn't find out in Linux if there is an option to use system certificates and if there's even such a store. <\/p>\n<p>We will connect via the domain. Therefore, we need a certificate from the certificate authority where our certificate was purchased.<\/p>\n<p>The entire connection is done in one window. We choose our network:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/9e05f44a52ee7290921b5b74df718a0c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>anonymous \u2014 client<br \/>\ndomain \u2014 the domain for which the certificate was issued<br \/>\n<\/i><\/p>\n<h3>Android<\/h3>\n<p><\/p>\n<h4>non-Samsung<\/h4>\n<p>\nStarting from version 7, when connecting to WiFi, you can use system certificates by specifying only the domain:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/f935493cbe35f5a19c4da8bb5632604f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>domain \u2014 the domain for which the certificate was issued<br \/>\nanonymous \u2014 client<br \/>\n<\/i><\/p>\n<h4>Samsung<\/h4>\n<p>\nAs mentioned above, Samsung devices cannot use system certificates when connecting to WiFi and do not have the option to connect via domain. Therefore, it is necessary to manually add the root certificate of the certificate authority (ca.pem, obtained from the Radius server). Here we will use a self-signed certificate.<\/p>\n<p>Download the certificate to your device and install it.<\/p>\n<p><b class=\"spoiler_title\">Installing the certificate<\/b><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/d02770f35c44a618f2f6243085c258b8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/eb9ec984d5e68824ebd0b138551a87c2.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/2c5c95c339b00085845470fdff56932e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/1561758abad60a168e067f1ecb0b94f5.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAt this point, you will need to set a screen unlock pattern, PIN code, or password if it's not already set:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/eeb9189ecdb8c255f2b76918ec1954b5.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/741c2f6df3e50c5ebb94c76e907efb33.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>I showed the complex method of installing the certificate. On most devices, it is enough just to click on the downloaded certificate.<\/i><\/p>\n<p>Once the certificate is installed, you can proceed to connect:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/4e2a8716b30634b3effdb0f2cbf781af.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>certificate \u2014 specify the one you installed<br \/>\nanonymous user \u2014 guest<br \/>\n<\/i><\/p>\n<h3>macOS<\/h3>\n<p>\nApple devices out of the box can only connect to EAP-TLS, but you still need to upload the certificate to them. To specify a different connection method, you need to use Apple Configurator 2. Accordingly, you first need to download it to a Mac, create a new profile, and add all the necessary WiFi settings.<\/p>\n<p><b class=\"spoiler_title\">Apple Configurator<\/b><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/1864dedc371b851dbf2594eff3ec7fc7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/0847466b361f681bcfcabee92f1ac885.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>Here, specify your network name<br \/>\nSecurity Type \u2014 WPA2 Enterprise<br \/>\nAccepted EAP Types \u2014 TTLS<br \/>\nUser Name and Password \u2014 leave empty<br \/>\nInner Authentication \u2014 PAP<br \/>\nOuter Identity \u2014 client <br \/>\n<\/i><\/p>\n<p><i>Trust tab. Here, specify our domain<\/i><\/p>\n<p>All done. The profile can be saved, signed, and distributed to devices.<\/p>\n<p>Once the profile is ready, it needs to be downloaded on the Mac and installed. During the installation process, you will need to provide the usernmae_ldap and password_ldap of the user:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/d7cb1cbcfd1de930d0718c1596bc60d7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/dd2e90a77fd9b64f6a98b0c0b21a080c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/c1cb62ec60fc835353c5e409a138f0be.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>iOS<\/h3>\n<p>\nThe process is similar to macOS. You need to use the profile (you can use the same one as for macOS. How to create a profile in Apple Configurator is shown above).<\/p>\n<p>Download the profile, install it, enter the credentials, and connect:<\/p>\n<p><img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/9e2be411c0dfb427bfd54ad0b1f42dcb.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/d637fa93c0bcf09d1a5eb3701f769d4f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/0908737918cd81cbf3e1ebf9ba0d9820.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/3821dc0bd6f866730575c6ceb3d5bbfb.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/b4b0bf189ac037345e33e7864bfb2ad8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti\" src=\"\/wp-content\/uploads\/2019\/08\/f5f9b7168ac14b67d6f4753d050a742e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThat's it. We have configured the Radius server, synchronized it with FreeIPA, and instructed Ubiquiti access points to use WPA2-EAP.<\/p>\n<h2>Possible questions<\/h2>\n<p>\n<b>Q:<\/b> how to transfer the profile\/certificate to the employee?<\/p>\n<p><b>A:<\/b> I store all certificates\/profiles on FTP accessible via the web. I set up a guest network with speed limits and internet access only, except for FTP. <br \/>\nAuthentication lasts for 2 days, after which it resets and the client is left without internet. Thus, when an employee wants to connect to WiFi, they first connect to the guest network, access the FTP, download the necessary certificate or profile, install it, and then can connect to the corporate network.<\/p>\n<p><b>Q:<\/b> why not use the MSCHAPv2 scheme? isn't it safer?<\/p>\n<p><b>A:<\/b> Firstly, this scheme works well on NPS (Windows Network Policy System), but in our implementation, it requires additional LDAP (FreeIPA) configuration and storing password hashes on the server. Additional settings are undesirable as they can lead to various synchronization issues. Secondly, the hash is MD4, which does not significantly improve security.<\/p>\n<p><b>Q:<\/b> is it possible to authorize devices by MAC addresses?<\/p>\n<p><b>A:<\/b> NO, it is not secure; an attacker can spoof MAC addresses, and moreover, MAC address authorization is not supported on many devices. <\/p>\n<p><b>Q:<\/b> why use all these certificates at all? can one connect without them?<\/p>\n<p><b>A:<\/b> Certificates are used to authenticate the server. That is, when a device connects, it verifies whether this is a trustworthy server or not. If it is, the authentication continues; if not, the connection is closed. It is possible to connect without certificates, but if a malicious user or neighbor sets up a radius server and an access point with the same name as ours, they can easily intercept user credentials (remember that they are transmitted in plain text). When a certificate is used, the enemy will only see our fictitious User-Names \u2014 guest or client \u2014 and an error like \u2014 Unknown CA Certificate in their logs.<\/p>\n<p><b class=\"spoiler_title\">A bit more about macOS<\/b>Typically, reinstalling the system on macOS is done via the internet. In recovery mode, you need to connect the Mac to WiFi, and neither our corporate WiFi nor the guest network will work here. Personally, I set up another network, a standard one with WPA2-PSK, hidden, specifically for technical operations. Alternatively, you can create a bootable USB drive with the system in advance. However, if the Mac is from 2015 or later, you will also need to find an adapter for that USB drive.)<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/463225\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0423\u0436\u0435 \u0431\u044b\u043b\u0438 \u043e\u043f\u0438\u0441\u0430\u043d\u044b \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0438\u043c\u0435\u0440\u044b \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0433\u043e WiFi. \u0417\u0434\u0435\u0441\u044c \u044f \u0440\u0430\u0441\u043f\u0438\u0448\u0443 \u043a\u0430\u043a \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043b \u043f\u043e\u0434\u043e\u0431\u043d\u043e\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0441 \u043a\u043e\u0442\u043e\u0440\u044b\u043c\u0438 \u043f\u0440\u0438\u0448\u043b\u043e\u0441\u044c \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u0442\u044c\u0441\u044f \u043f\u0440\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043d\u0430 \u0440\u0430\u0437\u043d\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445. \u0411\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0443\u0436\u0435 \u0438\u043c\u0435\u044e\u0449\u0435\u0439\u0441\u044f LDAP \u0441 \u0437\u0430\u0432\u0435\u0434\u0435\u043d\u043d\u044b\u043c\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c\u0438, \u043f\u043e\u0434\u043d\u0438\u043c\u0435\u043c FreeRadius \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u043c WPA2-Enterprise \u043d\u0430 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0435 Ubnt. \u0412\u0440\u043e\u0434\u0435 \u0432\u0441\u0435 \u043f\u0440\u043e\u0441\u0442\u043e. \u041f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c\u2026 \u041d\u0435\u043c\u043d\u043e\u0433\u043e \u043e \u043c\u0435\u0442\u043e\u0434\u0430\u0445 EAP \u041f\u0440\u0435\u0436\u0434\u0435 \u0447\u0435\u043c \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u0442\u044c \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27785,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-37065","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/wifi-enterprise-freeradius-freeipa-ubiquiti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/wifi-enterprise-freeradius-freeipa-ubiquiti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:15:33+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:15:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/wifi-enterprise-freeradius-freeipa-ubiquiti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47WiFi Enterprise. FreeRadius + FreeIPA + Ubiquiti | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/wifi-enterprise-freeradius-freeipa-ubiquiti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:15:33+00:00","article:modified_time":"2019-10-31T19:15:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37065","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 05:57:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:36:42","updated":"2026-01-22 05:57:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=37065"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37065\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/27785"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=37065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=37065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=37065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}