Wirelessยถ
SSIDโsยถ
Weโre maintaining two wireless SSIDโs:
SSID |
Usage |
Access method |
|---|---|---|
|
Clients WLAN |
mTLS client certificate |
|
Devices WLAN |
Passphrase |
|
Guest WLAN |
Vouchers |
Hint
Guests can connect to the confirm guests network. Just give them a voucher for it and theyโre fine to go.
Guest vouchersยถ
To create new guest vouchers, login into the UniFi Cloud Key, and go to:
Insights (sidebar)
Hotspot (top-level tab)
Vouchers (sub-level tab)
Wireless client on macOS & iOSยถ
To connect to the confirm clients WLAN, use the following configuration with macOS & iOS:
Mode |
EAP-TLS |
Identity |
|
Username |
Must match the CN of the certificate (i.e. your username) |
Wireless clients on Linuxยถ
If youโre running Linux, use the following configuration:
Security |
WPA & WPA2 Enterprise |
Authentication |
TLS |
Identity |
Must match the CN of the certificate (i.e. your username) |
CA certificate |
|
Private key |
Wireless clients on Windowsยถ
If youโre a Windows (10) user (shame on you), use the following pain-in-the-ass thanks to an obviously mentally ill Microsoft developer who wants to see the world burn:
Add to
confirmCA, and trust it (rename to*.crt& add to trusted root CA store)Add the client certificate
Do NOT try to connect to the
confirm clientsWLAN at all (this is important, no joke)In case you did try before, right-click the
confirm clientsWLAN, and chooseForgetHit
Windows + R, and entercontrolGo to
Network and Internet, and thenNetwork and Sharing CenterClick on
Set up a new connection or networkSelect
Manually connect to a wireless networkUse
confirm clientsas network name withWPA2-Enterpriseas security typeUncheck both checkboxes (auto start connection & connect even if not broadcasting)
Click
NextClick on
Change connection settings(this only appears if WLAN wasnโt configured before)Go to
Security, and change the authentication method toSmart Card or other certificateClick on
SettingsSelect
confirmCAas trusted root certificate authorityCheck the checkbox
Use a different user name for the connectionConfirm the settings
Connect to the
confirm clientsSelect your certificate
The user name must match the CN of the certificate (i.e. your full name)
Hint
Heads up: once youโve messed something up in Windows, thereโs AFAIK no way to reopen the proper (classic) WLAN settings dialog again. You have to forget the network and re-add it manually. Windows will happily give you the dumbed-down Windows 10 settings panel, but not the classic one.
Warning
To anyone considering asking me, Dominique Barton, to connect their sad little Windows notebook to WLAN: No. No! Go step on a LEGO. Figure it out yourself, or for the love of all that is holy, get a real OS (Linux or macOS). Microsoft and Windows are a crime against humanity โ and possibly against good taste, networking, and your remaining sanity.