Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iPad-iPhone connectivity on Enterprise Wifi.

I have been tasked with getting iPad’s and iPhones connected to our internal wireless network.

Currently:
We use two Cisco 4400 Wireless LAN Controllers with 1131AG access points. The WLC’s are located at our two largest offices. AP’s operate in Local mode where they coexist with the WLC and HReap at all other locations.

We use Windows 2008 R2 server as our domain enterprise CA and NPS (IAS) server.

The laptop WLAN is configured for 802.1x w/WEP passing the computer (not user) certificate through to the NPS server to grant access. Laptops currently running XP.

Wireless configuration and root CA certificates are distributed via Group Policies.

This all works well.

Introduce....the iPad!

I started with this Blog on technet ( http://blogs.technet.com/b/askds/archive/2010/11/22/ipad-iphone-certificate-issu ance.aspx )

Configured the following on a new WLAN.
WPA+WPA2 802.1x AES (no TKIP). AAA server is the same NPS/CA server used by the Laptops.

If (on the iPad) I manually select the new WLAN it prompts me for a user name and password. I enter it and it fails. This is actually expected by choice as we want the computer based certificate to be used for authentication. I mention this because I actually see the NPS server log a failed auth request with my user name etc. I know that the communication is getting through the Cisco WLAN WLC configuration.

Introduce the iPhone Configuration Utility

Created a profile to push the Wifi, enterprise root CA certificate, and SCEP. When I install the profile to the iPad it attempts to connect and errors with “Profile failed to install. A Network Error has occurred.”

The iPhone Configuration Utility Console logs the error below.

Mar 16 09:55:56 iPad profiled[1722] <Warning>: MC|Profile wifiprofile.hro.com failed to install with error: NSError 0x1ed8d170:
Desc : Profile Failed to Install
Sugg : A network error has occurred.
US Desc: Profile Failed to Install
US Sugg: A network error has occurred.
Domain : MCInstallationErrorDomain
Code : 4001
Type : MCFatalError
...Underlying error:
NSError 0x1ed8cdb0:
Desc : The profile HRO Wifi Profile could not be installed.
Sugg : A network error has occurred.
US Desc: The profile HRO Wifi Profile could not be installed.
US Sugg: A network error hasoccurred.
Domain : MCProfileErrorDomain
Code : 1009
Type : MCFatalError
Params : (
"HRO Wifi Profile"
)
...Underlying error:
NSError 0x1ed8c480:
Desc : A network error has occurred.
Sugg : bad URL
US Desc: A network error has occurred.
Domain : MCSCEPErrorDomain
Code : 22005
Type : MCFatalError
...Underlying error:
NSError 0x1ed40dc0:
Desc : bad URL
Domain : NSURLErrorDomain
Code : -1000
Type : MCFatalError
Extra info:


Questions?

Bad URL??? The URL in the profile is correct and I can access it from any PC. Could this be a DNS issue, in that if the device is not allowed on the wifi yet, how can it perform a DNS lookup?

The Blog (see above) has left me with a few questions on the SCEP settings
Does the referenced “Subject” need to be the full AD path (backwards per the blog). i.e. AD: CN=ipad,OU=<device>,OU=<subcontainer>,OU=<subcontainer>,DC=Domain,DC=<rootdomai n>,DC=com

iPhone : O=com,O=<rootdomain>......
Does the O in fact translate to DC or should I be using DC instead?

NDES (on the CA) was installed using 2048 bit key. Does the SCEP setting in the utility need to match this or the key length of the root CA certificate. How do I determine the key length of the cert, I have looked at the properties of the CA cert but do not see it.

Per one of the blogs comments, do I in fact need a $ at the end of the device name?

This solution is still going to require that I have the device (iphone, ipad) in hand to install the profile. This will be a challenge with remote offices across the western US.

Ideally I would prefer for them to be prompted for the NDES key that I can read to them.

Thanks All

iOS 4

Posted on Mar 16, 2011 1:29 PM

Reply
5 replies

Aug 12, 2011 5:33 AM in response to russell.laplante

Hi Russell


Did you ever get this to work? I'm in a similar position - have now configured a separate WPA2 wireless network with a separate RADIUS server to allow me to "mess around" a bit more. I can issue a certificate from the NDES server, but I can't get the iPad to negotiate a successful 802.1x authentication.


I'm unsure if this is because the certificate isn't right, or if it's the RADIUS policies that are wrong. I have tried making several changes and still no luck so far. In particular, I had the same question as you about whether a computer object for the iPad should be created in AD. I have tried with and without with no joy. I also tried pointing the SCEP configuration to my AD user object to try a user based certificate to no avail.


I haven't been able to find anyone with a good end-to-end knowledge of how this should be configured - if you've managed this I'd be very interested to hear how you did it!


Thanks.

Sep 23, 2011 12:56 PM in response to kevinrcunningham

I was following this article: http://blogs.technet.com/b/askds/archive/2010/11/22/ipad-iphone-certificate-issu ance.aspx and i was getting same error like you. After i did some changes and fixed it works on my ipad - hadn't time to test with other devices.

My changes:

url for SCEP server changed to http instead of https

and subject changed to simple: O=domain,CN=ipad


it worked

Feb 23, 2012 6:20 AM in response to dar2kas

Hi dar2kas,


Are those the only 2 changes which you have done and it worked?

I'm having the same issue with auth on the radius? I can install cert with no issues by following that tutorial but for some reason I think the iPad is identified as an user account?...not sure.


This is the error on NPS Windows 2008 R2 Server; I put all the "blame" on the Subject settings and tried to add only O=domain, CN=ipad, tried to add $ after CN name as advised on these forums...no luck 😟




Network Policy Server denied access to a user.


Contact the Network Policy Server administrator for more information.


User:

Security ID: NULL SID

Account Name: iPad1

Account Domain: Domain

Fully Qualified Account Name: Domain\iPad1


Client Machine:

Security ID: NULL SID

Account Name: -

Fully Qualified Account Name: -

OS-Version: -

Called Station Identifier: 000B86070E00

Calling Station Identifier: 286ABACDFC41


NAS:

NAS IPv4 Address: 172.xx.0.1

NAS IPv6 Address: -

NAS Identifier: 172.xx.0.1

NAS Port-Type: Wireless - IEEE 802.11

NAS Port: 1


RADIUS Client:

Client Friendly Name: Aruba

Client IP Address: 172.xx.0.x


Authentication Details:

Connection Request Policy Name: Wifi

Network Policy Name: -

Authentication Provider: Windows

Authentication Server: Server1.local.domain

Authentication Type: EAP

EAP Type: -

Account Session Identifier: -

Logging Results: Accounting information was written to the SQL data store.

Reason Code: 8

Reason: The specified user account does not exist.

Feb 26, 2012 6:35 AM in response to 1338

Update: I managed to do it by creating an account in AD, do the name mappings and associate the certificate from CA ( exported first as X.509 one) then disable the "Ignore user dial-in proprieties" from Network Policies on the NPS server.


Not sure if this is the best way forward but it works for the moment...

iPad-iPhone connectivity on Enterprise Wifi.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.