PEAP? WPA2 enterprise?

Discussion in 'Networking' started by rgarg, Aug 9, 2008.

  1. rgarg

    whalertly

    Joined:
    Sep 4, 2008
    Messages:
    15
    Likes Received:
    0
    Okay, so I got enterprise now but it is unable to connect to any Wifi spot; I can see them, try to connect, but not get it. This includes my wifi that i could us before

    however, ethernet cords work
     
    whalertly, Oct 8, 2008
    #61
  2. rgarg

    szesea

    Joined:
    Sep 25, 2008
    Messages:
    49
    Likes Received:
    0
    i hv finished the installation.

    however,during the process, sth like below was shown, is it alright? (connection refused)

    also after rebooting, i can't open the network centre under settings, though i can still connect wifi
    therefore i can only start the network connection in the icon tray on the bottom right, but sometimes it can't be shown up and i need to restart the computer again (and then it will pop up !) anyone hv the same problem?

    actually i want to start the network centre under settings like before, pls help
    thx
     
    szesea, Oct 10, 2008
    #62
  3. rgarg

    hucklebury

    Joined:
    Oct 16, 2008
    Messages:
    3
    Likes Received:
    0
    First off, thanks for all the work people put into this forum; it's much appreciated, especially by those of us a little unsure of what's going on inside Linpus. :p

    So, I need to connect to my university wi-fi network which they've just upgraded. I've done the network manager upgrade without any problems working from this thread. But the new, bigger and better network manager still doesn't offer me enough settings to get into the uni system - the instructions (which are clearly set up for Unbuntu) are:

    * Set ‘Wireless security’ to WPA2 Enterprise
    * Set ‘EAP method’ to PEAP
    * Set ‘Key type’ to AES :cry:
    * Set ‘Identity’ to your Uinversity Username
    * Type your normal University password into the password box
    * Leave ‘Anonymous Identity’ blank
    * Leave ‘Client certificate file’ set to (none)
    * Click the ‘CA Certificate file’ option, a file open window should popup - locate the ja-ct-root.pem file you downloaded earlier, select it and click open
    * Leave ‘Private key file’ set to (none)
    * Leave ‘Private key password’ blank
    * Click ‘Login to network’

    So I'm stuck on line 3 of these instructions... Does anyone know a way of upgrading Linpus further to get these settings, as I've got this OS behaving (apart from the network) as I would like? Or do I have to bite the bullet and go for X/K/Ubuntu?
     
    hucklebury, Oct 16, 2008
    #63
  4. rgarg

    IMSancho

    Joined:
    Aug 14, 2008
    Messages:
    95
    Likes Received:
    0
    Location:
    Australia
    AES should be detected when it sees that it's a WPA2 network, so you don't need to specify that. Basically as long as you download that cert file and point network manager to it, and then set the other options as listed in your Uni's guide you should be all set. Try connecting a few times with

    Security: WPA & WPA2 Enterprise
    Authentication: PEAP
    Anonymous Identity: <blank>
    CA Certificate:*path you saved the cert to here*
    PEAP Version: Version 0
    Inner Authentication: MSCHAPv2

    And your username and password in the appropriate fields. If that doesn't work try PEAP Version 1 (again give it a few tries, mine sometimes won't connect first go) If you still can't get on with that could you post a link to the settings guide for your university?

    szesea: The connection refused messages are a bug in the implementation of sudo under fedora, you'll see that every time you use sudo. I've never used network center under settings, but yes it seems it doesn't work with this version of network manager, what do you need to set in there that can't be done in NetworkManager? There are a few threads around about networkmanager not starting, I've not had it myself so can't offer a solution but have a bit of a search around the forums for possible fixes.
     
    IMSancho, Oct 20, 2008
    #64
  5. rgarg

    szesea

    Joined:
    Sep 25, 2008
    Messages:
    49
    Likes Received:
    0
    one more question about CA certificate

    my uni use Equifax_Secure_Certificate_Authority.cer

    however, i can't select it since it only allows me to choose DER or PEM certificates (.der , or .pem)

    anyone know how to solve it ?

    thx
     
    szesea, Oct 21, 2008
    #65
  6. rgarg

    IMSancho

    Joined:
    Aug 14, 2008
    Messages:
    95
    Likes Received:
    0
    Location:
    Australia
    You should be able to convert the file to PEM with openssl
    Code:
    openssl x509 -in Equifax_Secure_Certificate_Authority.cer -outform PEM -out cert.pem
    Although it is probably already in PEM format and just renaming the file to .pem so that networkmanager will allow you to select it is all you'll need to do.
     
    IMSancho, Oct 21, 2008
    #66
  7. rgarg

    szesea

    Joined:
    Sep 25, 2008
    Messages:
    49
    Likes Received:
    0
    i hv tried to rename it into .pem, and i can select the file this time
    but afterward, the 'connect' button becomes gray after i choose the CA cert

    so i can't connect!

    btw, here is my uni WiFi Service Setting Values
    SSID : eduroam
    Authentication : WPA
    Data Encryption : TKIP
    EAP Type PEAP : (EAP-MSCHAPv2)
    Trusted Root Certification Authorities : Equifax Secure Certificate Authority (Equifax_Secure_Certificate_Authority.cer)
    Server Certificate : 802.1x.hku.hk


    bold text are those i hv difficulties to deal with.

    pls help, thx
     
    szesea, Oct 21, 2008
    #67
  8. rgarg

    IMSancho

    Joined:
    Aug 14, 2008
    Messages:
    95
    Likes Received:
    0
    Location:
    Australia
    A few others had trouble with certs earlier in this thread. As I don't connect to any networks that require certs I haven't had a chance to try it out, but have a look at Yodersj and Dros's posts here as it seems to be the same issue you are having.
     
    IMSancho, Oct 22, 2008
    #68
  9. rgarg

    IMSancho

    Joined:
    Aug 14, 2008
    Messages:
    95
    Likes Received:
    0
    Location:
    Australia
    Seems quite a few People are redistributing this script outside these forums, and while I don't have a problem with that please provide a link back to this post so others can get help if it doesn't work, and don't change the wording slightly and pass it off as something you've made :roll:
     
    IMSancho, Oct 24, 2008
    #69
  10. rgarg

    szesea

    Joined:
    Sep 25, 2008
    Messages:
    49
    Likes Received:
    0
    sorry, can u tell me more abt what is openssl ?

    thx
     
    szesea, Oct 24, 2008
    #70
  11. rgarg

    IMSancho

    Joined:
    Aug 14, 2008
    Messages:
    95
    Likes Received:
    0
    Location:
    Australia
    http://www.openssl.org/ Plenty to read at the official site

    Sounds like you are having the same issue as yodersj was though, so try reading their post and maybe shoot them a private message and they may be able to help you with security certificates.
     
    IMSancho, Oct 24, 2008
    #71
  12. rgarg

    muuuuuu

    Joined:
    Oct 9, 2008
    Messages:
    3
    Likes Received:
    0
    Hi everyone,

    I write a mini tutorial on how to connect to WPA-Enterprise networks.

    In AspireOne, NetworkManager can not support PEAP authentication and WPA-Enterprise network. If you want use PEAP authentication and WPA-Enterprise network, you can use command line, the step is :
    1. open a terminal (ALT+F2 and enter "ternmial") .
    2. get root privilege ("sudo su -")
    3. stop NetworkManager and wpa_supplicant
    ("/etc/init.d/NetworkManager stop"; "/etc/init.d/wpa_supplicant stop")
    4. then use editor mousepad to write config file ("mousepad
    /etc/wpa_supplicant/wpa_supplicant_wpa2.conf")
    If your AP use EAP-TLS with WPA, the content like this :
    #----------------------------------------------------------
    ctrl_interface=/var/run/wpa_supplicant
    ctrl_interface_group=wheel
    network={
    ssid="work"
    scan_ssid=1
    key_mgmt=WPA-EAP
    pairwise=CCMP TKIP
    group=CCMP TKIP
    eap=TLS
    identity="[email protected]"
    ca_cert="/etc/cert/ca.pem"
    client_cert="/etc/cert/user.pem"
    private_key="/etc/cert/user.prv"
    private_key_passwd="password"
    }
    #----------------------------------------------------------
    If your AP use WPA-RADIUS/EAP-PEAP/MSCHAPv2 with RADIUS
    servers that use old peaplabel, the content like this:
    #----------------------------------------------------------
    ctrl_interface=/var/run/wpa_supplicant
    ctrl_interface_group=wheel
    network={
    ssid="example"
    scan_ssid=1
    key_mgmt=WPA-EAP
    eap=PEAP
    identity="[email protected]"
    password="foobar"
    ca_cert="/etc/cert/ca.pem"
    phase1="peaplabel=0"
    phase2="auth=MSCHAPV2"
    }
    #----------------------------------------------------------
    5. use wpa_supplicant to connect the AP ("wpa_supplicant -Dwext
    -iath0 -d -c/etc/wpa_supplicant/wpa_supplicant_wpa2.conf")
    6. when the output of wpa_supplicant show
    GROUP_HANDSHAKE->COMPLETED, use dhclient get the network's configuration
    at another terminal with root privilege ("killall dhclient"; "dhclient
    ath0")
    7. now you can access the network with wireless.
     
    muuuuuu, Oct 27, 2008
    #72
  13. rgarg

    Guest Guest

    The script worked really well, thanks.

    However, is there anyway to stop the NetworkManager icon disappearing after going in to sleep and any way to restore the ability to click on 'Network Center' in the Settings? Since using the script the icon seems to be dead and nothing happens when I click it.

    Thanks!
     
    Guest, Oct 27, 2008
    #73
  14. rgarg

    CalebW

    Joined:
    Oct 16, 2008
    Messages:
    15
    Likes Received:
    0
    The script worked for me - thanks very much, IMSancho. And with the instructions given in this thread, it remembers my passwords and the system tray applet doesn't disappear after coming out of Sleep - great stuff!
     
    CalebW, Oct 28, 2008
    #74
  15. rgarg

    ebustelo

    Joined:
    Jul 28, 2008
    Messages:
    20
    Likes Received:
    0
    This is for those who updated NetworkManager with IMSancho script.
    After doing this my network manager was able to connect to my university WPA-entreprise,
    but at the same time it always asked me for any WPA key before connecting to any network.
    Finally the solution for me was to edit the file: /etc/xdg/autostart/nm-applet.desktop
    and edit the line: Exec=nm-applet --sm-disable
    All I had to do was to add "sudo" in this way: Exec=sudo nm-applet --sm-disable

    After this I had two reboot to times and now NetworkManager can remember the WPA keys!
    -------------------
    A second part of my story involves stupidly using live update so the Network Manager went back to the original.
    I used the IMSancho script for a second time and I got updated again for WPA-entreprise.
    However the previous solution was not working now... ;-(

    Finally, I have downloaded NetworkManager109.sh from http://update.linpus.com/ACER/AspireOne/v1.0.9/
    After running it, I have got the original NetworkManager again, but now the IMSancho script and the edition of the nm-applet.desktop file worked again!

    I hope this can help to someone with the same problem I had.
     
    ebustelo, Oct 29, 2008
    #75
  16. rgarg

    Lourinho

    Joined:
    Oct 29, 2008
    Messages:
    2
    Likes Received:
    0
    Hi all I receive today my acer aspire, and I've notice that I couldnt config WPA2 enterprise in this OS Linpus.

    I saw IMSancho post, and I did exacly like I says, but I've a problem when a run his script its fine, but when I reboot I cant connect to my private network throught wireless. It keep saying Disconnected, Disconnected.

    I cant open Network Center Also.

    I did the updates before IMSancho script, can anyone help me with this because I need to connect my uni internet :( and my home wireless.

    Regards
     
    Lourinho, Oct 29, 2008
    #76
  17. rgarg

    tpc2

    Joined:
    Nov 18, 2008
    Messages:
    3
    Likes Received:
    0
    I'm very much a newbie; just got my AA1 last week, my first netbook, some Linux experience (old RH versions, then Libranet, then Ubuntu), but none with Linpus and because I haven't dabbled in Fedora none with Yum...

    This part worries me; I'm not really looking to track yum repositories to figure out what to put in/keep out (I've added Skype to my AA1, and a couple of other things, but don't really want to track updates on what is really an Acer-customized distro).
    - Does LiveUpdate really move NM *back* versions?!? (yes, that was rhetorical - I'm not saying it didn't happen to you because I think you'd be able to tell :) but it seems like a braindead thing to do...)
    - Is there any way to STOP LiveUpdate from backversioning updated software? (I haven't looked at LiveUpdate - I was expecting it's just a set of scripts?)
    - So, if you don't use LiveUpdate, what do you do to keep up with security patches?

    Thanks!

    Tom
     
    tpc2, Nov 18, 2008
    #77
  18. rgarg

    ebustelo

    Joined:
    Jul 28, 2008
    Messages:
    20
    Likes Received:
    0
    ebustelo, Nov 18, 2008
    #78
  19. rgarg

    Liquid_Cool

    Joined:
    Dec 19, 2008
    Messages:
    1
    Likes Received:
    0
    I ran IMSancho's script to update my Network Manager and get WPA enterprise. It worked great, but I was still unable to connect to my university's wireless. After much exhaustion, I've given up.

    Does anyone know how to undo IMSancho's script? I want my original network manager back. In fact, I would like to do a full system restore, but my AAO didn't come with any recovery disks. And all the restoring methods I have found require me to do a backup first, which I assume will restore my computer to how it is now, and not back to factory. Can anyone help me with either of these problems?


    EDIT: I have finally got a connection! And I got my hands on a recovery disk. Now all I have to do is stop Network Manager from stopping after sleep, make its links on the desktop work again, and get it to remember my passwords.
     
    Liquid_Cool, Dec 27, 2008
    #79
  20. rgarg

    flavouredvanilla

    Joined:
    Jan 9, 2009
    Messages:
    31
    Likes Received:
    0
    Location:
    England, United Kingdom
    Okay so this is really pissing me off.

    I bought my AAO because my HP dv7-1020ae is 3.5kg.

    Carrying this around with me to and from and around University was doing serious damage to my back and shoulders and since I'm a student of the school of computing I need some from of computer with me all the time.

    So I discovered that my AAO won't connect to the University wireless because when we connect (this is going from my HP laptop/Vista setup) it asks for "additional credential information" where we enter out university username and password.

    As the AAO doesn't support this is just refuses to let me connect to the network. It sees the wifi but displays blank fields on the connection wizard.

    I thought this would be my solution but so far when I've tried to use these solutions I've managed to install and update the network manager but it then wouldn't let me connect to my home network. So far I've restored my AAO three times. I've not tried connecting to my university network with the update but if I can't connect to my home network that isn't much use. I need the portabilty.

    Basically if someone can find a solution for me that's pretty simple (as I'm lazy and have enough to tackle with my course) I would be forever greatful.

    I'm a Windows/Mac student by "trade". Linux is pretty new territory for me...HELP!!!! :eek:

    EDIT: Okay I found the solution here: http://www.aspireoneuser.com/forum/viewtopic.php?f=34&t=1395&start=10
     
    flavouredvanilla, Jan 9, 2009
    #80
Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.