Security

 View Only
  • 1.  OnBoard with Chromebook

    Posted Jan 02, 2019 10:06 AM
    Hello

    I am having an issue with OnBoard and Chronebooks. I am able to get the Chromebook Onboarded with the proper certs but when the user tries to connect to the TLS network they are required to enter a name in the identity field. Shouldn’t Chromebook get that from the CN field or is this normal behavior? Thank You


  • 2.  RE: OnBoard with Chromebook

    Posted 5 days ago

    Did you ever find a solution to this issue? I've been having the same one.




  • 3.  RE: OnBoard with Chromebook

    Posted 3 days ago

    That's normal ChromeOS behaviour, not an Onboard problem. Chrome doesn't pull the EAP identity out of the cert CN the way the Windows and macOS supplicants do. It uses whatever sits in the Username field of the Wi-Fi policy you push from the Google Admin console, and if that field is empty the user gets prompted.

    Fix it in the Admin console network config rather than in ClearPass. Set Username to ${LOGIN_ID} or ${LOGIN_EMAIL} depending on whether your service expects a bare username or a UPN, and set Issuer pattern, Common name to your Onboard signing CA, something like "ClearPass Onboard Local Certificate Authority (Signing)". Without that second bit Chrome may not auto-select the Onboard cert either.

    Worth adding for anyone finding this later: Onboard on ChromeOS only works on managed devices with the admin-pushed Chrome extension. Unmanaged Chromebooks can't enrol through Onboard at all.



    ------------------------------
    Dustin Burns

    @Worldcom Exchange, Inc.


    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 4.  RE: OnBoard with Chromebook

    Posted 3 days ago

    Just a bit more lol. Enrollment depends on the ClearPass Onboard Chrome extension, and because of ChromeOS's security model, normal extensions installed from the Web Store don't have permission to write to the device certificate store. The extension has to be force-installed through an admin policy, which is why the Chromebook must be enrolled in a Google Admin domain for Onboard to work. Installing it directly from the Chrome Web Store isn't supported, so there's no BYOD path for an unmanaged Chromebook.

    Explaining this before was fun, lots of shrugs.



    ------------------------------
    Dustin Burns

    @Worldcom Exchange, Inc.


    If my post was useful accept solution and/or give kudos
    ------------------------------