Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

WPA2 Enterprise and iOS8

Seems after updating to iOS 8, I can no longer connect to my companies Cisco WPA2 Enterprise wireless network. This worked in iOS 7.

iPhone, iOS 8

Posted on Sep 17, 2014 10:40 AM

Reply
Question marked as Best reply

Posted on Sep 17, 2014 10:59 AM

Thanks for sharing.


Are you asking a question?

45 replies

Sep 17, 2014 7:09 PM in response to beejybone

I am getting a very similar problem after updating it iOS8. Our network is authenticated by an ACS 5 using EAP-TLS and we are now getting certificate errors on the ACS server when the iPhone tries to connect. It still works for iOS7 devices but not iOS8. Was anything changed in the way iOS uses certificates to authenticate?

Sep 18, 2014 8:50 AM in response to beejybone

I think I have found the problem. According to Apple:


iOS 8

802.1X
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: An attacker can obtain WiFi credentials
Description: An attacker could have impersonated a WiFi access point, offered to authenticate with LEAP, broken the MS-CHAPv1 hash, and used the derived credentials to authenticate to the intended access point even if that access point supported stronger authentication methods. This issue was addressed by disabling LEAP by default.


Since our WPA2 network used LEAP for authentication, disabling it broke the ability to login. The solution I found was to create a profile for wifi using the Apple Configurator tool and deploying it to our iOS devices. Everything working fine now.

Sep 19, 2014 11:42 AM in response to Km2086

Km2086 - your situation is extremely similar to our situation as we are also using ACS to authenticate with EAP-TLS. Works with iOS 7 but everyone who upgraded to iOS 8 can no longer connect. I don't see how iOS 8's non-support of LEAP would affect our situation as we do not authenticate using LEAP. Has anyone found a resolution yet besides disabling LEAP? Apple, if you are listening there are at least a few of us here with this issue so probably more that haven't reported it on a forum.

Sep 19, 2014 11:27 PM in response to robbgior

If I go to an Apple store, can they give me a new Iphone 5s with IOS7 ? My IOS8 5s is essentially bricked since I can't use Wi-Fi.


Really Apple ? How could you release software that bricks so many iPhones ?


One more reason to allow users to revert to the previous version of the OS.


It is one thing to have Jony Ive make unreadable text or pastel colour without contrast, but

another to disable Wi-Fi which is sort of essential these days.




I just upgraded (Sep 20th at 01:00 and it gave me 8.0

Sep 20, 2014 3:23 PM in response to JFMezei

An update I did some debug traces on my cisco router. There is an attempt at IOS 8 doing a login with EAP, but it fails.


This afternoon, I was allowed to install a 7.1.2 IPSW back on my iPhone, so I am a happy camper again. Wi-Fi is back up.


Hopefully Apple will produce something called "documentation" on exact what Wi-Fi protocols are still working on IOS 8.*


By the time 8.1 comes out, it is a given that if you install it and it still won't work, going back to 7.1.2 won't be allowed anymore.

Sep 23, 2014 11:44 PM in response to PranoyGiri

we also have the same issues. i also opened a bugreport a month ago (with ios 8 beta), but till today i got no response from apple. i also tried to get support on the phone and on apple developer forums, but also no luck. maybe we are lucky here?!


from what i've figured out apple has changed something their EAP modules. the authentication request shows the correct user but the radius is not able to understand the EAP messages sent by iOS8.


is there any official comment on this from apple or does anyone know a technical contact we could present this to? we have over 800 ipad/iphones which are connecting to the wifi and it is not working anymore.

WPA2 Enterprise and iOS8

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.