4 ms·
Sounds like you solved a lot of problems. I’d probably give up folding money for a DC with RADIUS solution that didn’t require me to rip hair out to renew the 8
by CodeWriter23 2y ago
Sounds like you solved a lot of problems. I’d probably give up folding money for a DC with RADIUS solution that didn’t require me to rip hair out to renew the 802.1X certs for our WiFi auth every year.
- elevation 2y agoIs the problem more in generating the certificates? Or in getting them uploaded into the controller? I'd seriously started to look into 802.1X but in the "remote work" use case, L2 protection doesn't buy you much because outside your building, an attacker can get L2 access at Starbucks. It seemed like a good feature to leave out of the MVP -- but now I'm wondering if it wouldn't be worth prioritizing.
- CodeWriter23 2y agoDoing RADIUS certs with Windows Server is just a pain every time I go to do it. Mostly lack of a good how to that covers the subset of what is needed to use RADIUS to get on the WiFi. The MS docs cover the kitchen sink, the patio and the front yard. And since I’m not a RADIUS practitioner, I’m never certain if I made a secure thing. (I guess the answer is no with the recent RADIUS design flaw disclosure). Perfect space for an appliance IMO, once RADIUS is cleaned up. I think any security-minded SMB will want to stop using WPA2 for WiFi authentication. I know we have one firewalled as a guest network, always getting hammered on from the outside. Can’t really advise what makes a good MVP for your effort. But if I could buy a box that was set and forget for this function, kept itself patched, complained when it couldn’t and wasn’t too expensive, I could acquire one where I work.
- elevation 2y agoCan you share your switch/AP vendor? To be able to support this feature I’d need to rack up some real hardware so I could run CI tests against it.
- CodeWriter23 2y agoUbiquiti. But I imagine making an 802.1X-authorized AP is possible just using linux.
- elevation 2y agoUbiquiti is a fantastic target for these kinds of integrations because the hardware is so affordable. Thanks for the data point!
- packetlost 2y agoIt was already asked, but I'm curious what the actual difficulty is with rotating certificates? Do the clients need certificates issued? Uploading the chain/authenticating certificate to the authenticator?