Link to home
Start Free TrialLog in
Avatar of PerimeterIT
PerimeterIT

asked on

Cisco Wifi: Https encryption on open access wifi portal

We have an existing Cisco wifi setup to provide open access wifi.
The Open access wifi SSID and VLAN have direct access to the internet and use external DNS.

However since the most recent patch HTTPS has gotten enabled on the wifi authentication portal and now all of our users get a certificate error when trying authenticate to this page.

Is there anyway to turn HTTPS off on the portal page?
Otherwise how can I setup the certificate?
The wifi portal is pointing to IP 1.1.1.1 internally, I wouldn't think that you could get a certificate assigned to that IP?
ASKER CERTIFIED SOLUTION
Avatar of Joey Yung
Joey Yung

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The wifi portal is pointing to IP 1.1.1.1 internally, I wouldn't think that you could get a certificate assigned to that IP?
At the moment you can, by using a SAN certificate, but after November this year you'll have to use DNS and a public FQDN as internal domain suffixes (such as .local, .lan, etc) and private IP addresses (10.0.0.0/8, 172.16.0.0/14 and 192.168.0.0/16) will no longer be allowed in 3rd-party certificate fields.

To that end, Joey is right.  You will need to disable the secureweb option to enable you to use HTTP instead.  However, this is not available on all WLCs, especially if they are running legacy code.  As well as this, you may hit a bug where users can only use HTTP authentication if you also enable HTTP management on the WLC.