We are a school using WPA2-Enterprise with PEAP for WiFi authentication. We use Microsoft NPS as the Radius server. The certificate in place is expiring and I need to renew it (first time for me). Currently we are using a certificate issued to nps..ca (which does not exist but the dns alias points to nps..local as CAs don’t issue certificates for internal domain names) which is working although all IOS and Android devices get a prompt to trust the certificate the first time they connect. Not a big deal, I can live with this. However the cert was issued by DigiCert before my time here and to renew it is $800 USD. This seems crazy expensive just to do what we’re doing with it. I’m looking at options such as using a Godaddy certificate ($80) or setting up an internal CA (free).<\/p>\n
Advertisement
Since we are using this certificate internally only, do I even need a third party certificate? It seems like users will be prompted regardless unless I distribute the certificate chain to all devices (not an option as the campus is filled with hundreds of BYOD devices we have no control over).<\/p>\n
Advertisement
Any reason not to just set up an internal CA and save money?<\/p>","upvoteCount":8,"answerCount":25,"datePublished":"2020-01-20T17:00:42.000Z","author":{"@type":"Person","name":"jlager","url":"https://community.spiceworks.com/u/jlager"},"suggestedAnswer":[{"@type":"Answer","text":"
We are a school using WPA2-Enterprise with PEAP for WiFi authentication. We use Microsoft NPS as the Radius server. The certificate in place is expiring and I need to renew it (first time for me). Currently we are using a certificate issued to nps..ca (which does not exist but the dns alias points to nps..local as CAs don’t issue certificates for internal domain names) which is working although all IOS and Android devices get a prompt to trust the certificate the first time they connect. Not a big deal, I can live with this. However the cert was issued by DigiCert before my time here and to renew it is $800 USD. This seems crazy expensive just to do what we’re doing with it. I’m looking at options such as using a Godaddy certificate ($80) or setting up an internal CA (free).<\/p>\n
Since we are using this certificate internally only, do I even need a third party certificate? It seems like users will be prompted regardless unless I distribute the certificate chain to all devices (not an option as the campus is filled with hundreds of BYOD devices we have no control over).<\/p>\n
Any reason not to just set up an internal CA and save money?<\/p>","upvoteCount":8,"datePublished":"2020-01-20T17:00:42.000Z","url":"https://community.spiceworks.com/t/certificate-setup-for-wpa2-enterprise-peap-authentication/747420/1","author":{"@type":"Person","name":"jlager","url":"https://community.spiceworks.com/u/jlager"}},{"@type":"Answer","text":"
all these devices connect internally?<\/p>","upvoteCount":0,"datePublished":"2020-01-20T17:42:49.000Z","url":"https://community.spiceworks.com/t/certificate-setup-for-wpa2-enterprise-peap-authentication/747420/2","author":{"@type":"Person","name":"paulsterud8853","url":"https://community.spiceworks.com/u/paulsterud8853"}},{"@type":"Answer","text":"
I’m not sure what you mean by internally but all these devices just connect to our campus WiFi SSID that uses WPA2-Enterprise authentication. I guess you could refer to that as internal use only?<\/p>","upvoteCount":0,"datePublished":"2020-01-20T17:45:46.000Z","url":"https://community.spiceworks.com/t/certificate-setup-for-wpa2-enterprise-peap-authentication/747420/3","author":{"@type":"Person","name":"jlager","url":"https://community.spiceworks.com/u/jlager"}},{"@type":"Answer","text":"