Wirelessยถ
SSIDโsยถ
Weโre maintaining two wireless SSIDโs:
SSID |
Usage |
Access method |
---|---|---|
|
Clients WLAN |
mTLS client certificate |
|
Devices WLAN |
Passphrase |
|
Guest WLAN |
Vouchers |
Hint
Guests can connect to the confirm guests
network. Just give them a voucher for it and theyโre fine to go.
Guest vouchersยถ
To create new guest vouchers, login into the UniFi Cloud Key, and go to:
Insights (sidebar)
Hotspot (top-level tab)
Vouchers (sub-level tab)
Wireless client on macOS & iOSยถ
To connect to the confirm clients
WLAN, use the following configuration with macOS & iOS:
Mode |
EAP-TLS |
Identity |
|
Username |
Must match the CN of the certificate (i.e. your username) |
Wireless clients on Linuxยถ
If youโre running Linux, use the following configuration:
Security |
WPA & WPA2 Enterprise |
Authentication |
TLS |
Identity |
Must match the CN of the certificate (i.e. your username) |
CA certificate |
|
Private key |
Wireless clients on Windowsยถ
If youโre a Windows (10) user (shame on you), use the following pain-in-the-ass thanks to an obviously mentally ill Microsoft developer who wants to see the world burn:
Add to
confirmCA
, and trust it (rename to*.crt
& add to trusted root CA store)Add the client certificate
Do NOT try to connect to the
confirm clients
WLAN at all (this is important, no joke)In case you did try before, right-click the
confirm clients
WLAN, and chooseForget
Hit
Windows + R
, and entercontrol
Go to
Network and Internet
, and thenNetwork and Sharing Center
Click on
Set up a new connection or network
Select
Manually connect to a wireless network
Use
confirm clients
as network name withWPA2-Enterprise
as security typeUncheck both checkboxes (auto start connection & connect even if not broadcasting)
Click
Next
Click on
Change connection settings
(this only appears if WLAN wasnโt configured before)Go to
Security
, and change the authentication method toSmart Card or other certificate
Click on
Settings
Select
confirmCA
as trusted root certificate authorityCheck the checkbox
Use a different user name for the connection
Confirm the settings
Connect to the
confirm clients
Select your certificate
The user name must match the CN of the certificate (i.e. your full name)
Hint
Please note, when you did something wrong in Windows, thereโs IMHO way to open the non-retarded WLAN settings again. Youโve to forget the WLAN network, and start adding it manually again. You can always open the Windows 10 kindergarden / retarded WLAN settings, but not the classic / non-retarded ones.
Warning
In case youโre thinking in asking me, Dominique Barton, if I can help you connecting your crappy & shitty Windows notebook to the WLAN: No โ step on a LEGO! Try it yourself, or FFS get a proper OS (Linux or macOS). Microsoft & Windows is a disgrace to humanity!