<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive portal, SSL and Intermediate CA problem in Wireless Questions and Best Practices</title>
    <link>https://community.ruckuswireless.com/t5/Wireless-Questions-and-Best/Captive-portal-SSL-and-Intermediate-CA-problem/m-p/32966#M1623</link>
    <description>Unfortunately it's a bit of an egg-on face / RTFM moment.&lt;BR /&gt;&lt;BR /&gt;we went back through the ssl configuration and re-installed the certificates in the correct order and it all works.&lt;BR /&gt;&lt;BR /&gt;in short the 'correct' order is "Root CA Cert, Intermediate Cert then device Cert."&lt;BR /&gt;&lt;BR /&gt;Hope this helps someone else tearing their hair out.</description>
    <pubDate>Fri, 07 Aug 2015 07:15:15 GMT</pubDate>
    <dc:creator>martin_christop</dc:creator>
    <dc:date>2015-08-07T07:15:15Z</dc:date>
    <item>
      <title>Captive portal, SSL and Intermediate CA problem</title>
      <link>https://community.ruckuswireless.com/t5/Wireless-Questions-and-Best/Captive-portal-SSL-and-Intermediate-CA-problem/m-p/32965#M1622</link>
      <description>Hi.&lt;BR /&gt;&lt;BR /&gt;We have recently had a ruckus wireless network installed. Everything from the AP's to the pair of ZD3050's configured as a smart-redundant pair is working well, except for the captive portal.&lt;BR /&gt;&lt;BR /&gt;We have 2 SSID's set up to authenticate separate captive portals from separate auth servers. It is functional to some degree however we are having problems with certificates.&lt;BR /&gt;&lt;BR /&gt;We purchased a cert (wifi.domain.ac.uk) from Janet which comes in 2 parts, intermediate CA and the device CA itself. &amp;nbsp; They both load onto the ZD fine, but when we try to access the login page from a mobile device or laptop then we get a certificate error, even though when we access the URL from a machine inside the network, everything is green.&lt;BR /&gt;&lt;BR /&gt;There are 2 possibilities as far as i can see. &amp;nbsp;using the command below we only get the intermediate cert back, not the full chain&lt;BR /&gt;&amp;gt;&amp;gt; openssl s_client -check wifi.tower.ac.uk:443&amp;nbsp;&lt;BR /&gt;Which returns this:&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;CONNECTED(00000003)depth=0 C = GB, ST = London, L = LONDON, O = Tower Hamlets College, CN = wifi.tower.ac.uk&lt;BR /&gt;&lt;B&gt;verify error:num=20:unable to get local issuer certificate&lt;/B&gt;&lt;BR /&gt;verify return:1&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;---&lt;BR /&gt;Certificate chain&lt;BR /&gt;&amp;nbsp;0 s:/C=GB/ST=London/L=LONDON/O=Tower Hamlets College/CN=wifi.tower.ac.uk&lt;BR /&gt;&amp;nbsp; &amp;nbsp;i:/C=BM/O=QuoVadis Limited/CN=QuoVadis Global SSL ICA G2&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;This seems to be wrong as the Webserver should respond with the entire chain not just a single cert:&lt;BR /&gt;&lt;A href="http://stackoverflow.com/questions/7587851/openssl-unable-to-verify-the-first-certificate-for-experian-url" rel="nofollow" target="_blank" title="Link http//stackoverflowcom/questions/7587851/openssl-unable-to-verify-the-first-certificate-for-experian-url"&gt;http://stackoverflow.com/questions/7587851/openssl-unable-to-verify-the-first-certificate-for-experi...&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Another ideas is there is something OCSP related to the captive portal we need to explicitly allow - but i'm new to that part of x509....&lt;BR /&gt;&lt;BR /&gt;Can any big forum brains point us towards an easy fix for this silliness?&lt;BR /&gt;&lt;BR /&gt;PS. we are running the latest firmware on the &lt;B&gt;ZD's: &amp;nbsp;&amp;nbsp;9.12.0.0 build 336&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Martin</description>
      <pubDate>Tue, 04 Aug 2015 14:07:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Wireless-Questions-and-Best/Captive-portal-SSL-and-Intermediate-CA-problem/m-p/32965#M1622</guid>
      <dc:creator>martin_christop</dc:creator>
      <dc:date>2015-08-04T14:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Captive portal, SSL and Intermediate CA problem</title>
      <link>https://community.ruckuswireless.com/t5/Wireless-Questions-and-Best/Captive-portal-SSL-and-Intermediate-CA-problem/m-p/32966#M1623</link>
      <description>Unfortunately it's a bit of an egg-on face / RTFM moment.&lt;BR /&gt;&lt;BR /&gt;we went back through the ssl configuration and re-installed the certificates in the correct order and it all works.&lt;BR /&gt;&lt;BR /&gt;in short the 'correct' order is "Root CA Cert, Intermediate Cert then device Cert."&lt;BR /&gt;&lt;BR /&gt;Hope this helps someone else tearing their hair out.</description>
      <pubDate>Fri, 07 Aug 2015 07:15:15 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Wireless-Questions-and-Best/Captive-portal-SSL-and-Intermediate-CA-problem/m-p/32966#M1623</guid>
      <dc:creator>martin_christop</dc:creator>
      <dc:date>2015-08-07T07:15:15Z</dc:date>
    </item>
  </channel>
</rss>

