[26732] in resnet
Re: Macs and 802..1x
daemon@ATHENA.MIT.EDU (Jason Healy)
Fri Sep 9 11:35:18 2011
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Transfer-Encoding: 8bit
Message-ID: <330A9E13-5589-40C8-8320-EB10EA4E30B2@logn.net>
Date: Fri, 9 Sep 2011 11:32:54 -0400
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: Jason Healy <jhealy@logn.net>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <fc.011edeaf03ad7176011edeaf03ad6646.3ad71bc@mcla.edu>
Listserver rejected my first posting with attachments, so we'll try again...
I'm pretty tied up today, but I'll attach what we have going right now:
http://web.suffieldacademy.org/~jhealy/resnet/
The first is a PDF of instructions for clearing out the 802.1X settings. Written for Snow Leopard, but they should work for Lion without too much difference.
The second is the script to pre-seed the certificate. Open it up in a text editor and paste in the PEM-encoded cert you want your Macs to trust for EAP. Then, make sure it's executable (chmod a+x scriptname.command) and let them at it.
I apologize for the cheese ASCII art, but we needed feedback that the users would actually read. We thought about embedding the cert in an installer package, but that makes it harder to debug, so we're sticking with this for now.
I'll see about scripting the 802.1X reset. I don't have time right now, but it should be something like:
networksetup -listalluserprofiles (gets list of 802.1x Profiles)
networksetup -deleteuserprofile <name of profile>
security delete-generic-password -D "802.1X Password" -l "WPA: Your SSID Here"
Note, that is *totally untested*, but if you have some scripters it might be enough of a head-start to get something working if you have students who can script...
Jason
--
Jason Healy | jhealy@logn.net | http://www.logn.net/
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________