Hotspot 2.0 Wi-fi connection radius ssl handshake errorSSL handshake alert: unrecognized_name error since upgrade to Java 1.7.0Tomcat trial Thawte certificateApache couchDB CA signed certificate issuesHTTP error 403.16 - client certificate trust issueQNetworkAccessManager ssl handshake failsNSURLSession Fails With SSL Page Using TLS 1.2Use TLS when server only sends its certificate and issuer is referenced by Authority Info Accessconfigure TLS certificate authroity in arangojscURL: SSL certificates on two different Amazon AMI servers not working the sameJava HTTPS client fails SSL handshake while curl succeeds

Greatest common substring

Drawing ramified coverings with tikz

Engineer refusing to file/disclose patents

What does this horizontal bar at the first measure mean?

Is there a word to describe the feeling of being transfixed out of horror?

On a tidally locked planet, would time be quantized?

How do ground effect vehicles perform turns?

Transformation of random variables and joint distributions

MAXDOP Settings for SQL Server 2014

Is XSS in canonical link possible?

Reply 'no position' while the job posting is still there

About a little hole in Z'ha'dum

My friend sent me a screenshot of a transaction hash, but when I search for it I find divergent data. What happened?

What is the gram­mat­i­cal term for “‑ed” words like these?

Divine apple island

How can "mimic phobia" be cured or prevented?

Query about absorption line spectra

Is a model fitted to data or is data fitted to a model?

Longest common substring in linear time

If a character with the Alert feat rolls a crit fail on their Perception check, are they surprised?

Translation of Scottish 16th century church stained glass

How do I extrude a face to a single vertex

Can somebody explain Brexit in a few child-proof sentences?

How do I implement a file system driver driver in Linux?



Hotspot 2.0 Wi-fi connection radius ssl handshake error


SSL handshake alert: unrecognized_name error since upgrade to Java 1.7.0Tomcat trial Thawte certificateApache couchDB CA signed certificate issuesHTTP error 403.16 - client certificate trust issueQNetworkAccessManager ssl handshake failsNSURLSession Fails With SSL Page Using TLS 1.2Use TLS when server only sends its certificate and issuer is referenced by Authority Info Accessconfigure TLS certificate authroity in arangojscURL: SSL certificates on two different Amazon AMI servers not working the sameJava HTTPS client fails SSL handshake while curl succeeds













0















We are trying to configure Hotspot 2.0 Wi-fi connection using our app.
This is how creating a Passpoint EAP-TTLS credentials looks like:



WifiEnterpriseConfig wifiEnterpriseConfig = new WifiEnterpriseConfig();
wifiEnterpriseConfig.setDomainSuffixMatch("hotspot.example.com");
wifiEnterpriseConfig.setRealm("hotspot.example.com");
wifiEnterpriseConfig.setEapMethod(WifiEnterpriseConfig.Eap.TTLS);
wifiEnterpriseConfig.setPhase2Method(WifiEnterpriseConfig.Phase2.MSCHAPV2);
wifiEnterpriseConfig.setIdentity("example");
wifiEnterpriseConfig.setPassword("example");
wifiEnterpriseConfig.setCaCertificate(cert); // getting cert part is omitted

WifiConfiguration wifiConfiguration = new WifiConfiguration();
wifiConfiguration.FQDN = "hotspot.example.com";
wifiConfiguration.providerFriendlyName = "hotspot.example.com";
wifiConfiguration.roamingConsortiumIds = new long[]111111;
wifiConfiguration.enterpriseConfig = wifiEnterpriseConfig;

int netId = wifiManager.addNetwork(wifiConfiguration);
wifiManager.enableNetwork(netId, true);



Device is trying to connect to Wi-Fi but fails on the ssl Radius server certificate verification stage with the following error:



2019-03-05 16:52:30.718 22634-22634/? W/wpa_supplicant: TLS: Certificate verification failed, error 2 (unable to get issuer certificate) depth 1 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018'
2019-03-05 16:52:30.718 22634-22634/? I/wpa_supplicant: wlan0: CTRL-EVENT-EAP-TLS-CERT-ERROR reason=1 depth=1 subject='/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018' err='unable to get issuer certificate'


Our Radius server has certificate which is signed by an Intermediate certificate. The Intermediate certificate is signed by a Root certificate which is trusted in the system (double checked it). So we specify the Intermediate certificate using method wifiEnterpriseConfig.setCaCertificate. Do we do it right, or we miss something?



Why do the we have to set some certificate manually at all? Why does the redius server can't be verified simply by the system root certs?



Does anyone know why the problem occurs and how to solve it? Any advices are welcome!










share|improve this question


























    0















    We are trying to configure Hotspot 2.0 Wi-fi connection using our app.
    This is how creating a Passpoint EAP-TTLS credentials looks like:



    WifiEnterpriseConfig wifiEnterpriseConfig = new WifiEnterpriseConfig();
    wifiEnterpriseConfig.setDomainSuffixMatch("hotspot.example.com");
    wifiEnterpriseConfig.setRealm("hotspot.example.com");
    wifiEnterpriseConfig.setEapMethod(WifiEnterpriseConfig.Eap.TTLS);
    wifiEnterpriseConfig.setPhase2Method(WifiEnterpriseConfig.Phase2.MSCHAPV2);
    wifiEnterpriseConfig.setIdentity("example");
    wifiEnterpriseConfig.setPassword("example");
    wifiEnterpriseConfig.setCaCertificate(cert); // getting cert part is omitted

    WifiConfiguration wifiConfiguration = new WifiConfiguration();
    wifiConfiguration.FQDN = "hotspot.example.com";
    wifiConfiguration.providerFriendlyName = "hotspot.example.com";
    wifiConfiguration.roamingConsortiumIds = new long[]111111;
    wifiConfiguration.enterpriseConfig = wifiEnterpriseConfig;

    int netId = wifiManager.addNetwork(wifiConfiguration);
    wifiManager.enableNetwork(netId, true);



    Device is trying to connect to Wi-Fi but fails on the ssl Radius server certificate verification stage with the following error:



    2019-03-05 16:52:30.718 22634-22634/? W/wpa_supplicant: TLS: Certificate verification failed, error 2 (unable to get issuer certificate) depth 1 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018'
    2019-03-05 16:52:30.718 22634-22634/? I/wpa_supplicant: wlan0: CTRL-EVENT-EAP-TLS-CERT-ERROR reason=1 depth=1 subject='/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018' err='unable to get issuer certificate'


    Our Radius server has certificate which is signed by an Intermediate certificate. The Intermediate certificate is signed by a Root certificate which is trusted in the system (double checked it). So we specify the Intermediate certificate using method wifiEnterpriseConfig.setCaCertificate. Do we do it right, or we miss something?



    Why do the we have to set some certificate manually at all? Why does the redius server can't be verified simply by the system root certs?



    Does anyone know why the problem occurs and how to solve it? Any advices are welcome!










    share|improve this question
























      0












      0








      0








      We are trying to configure Hotspot 2.0 Wi-fi connection using our app.
      This is how creating a Passpoint EAP-TTLS credentials looks like:



      WifiEnterpriseConfig wifiEnterpriseConfig = new WifiEnterpriseConfig();
      wifiEnterpriseConfig.setDomainSuffixMatch("hotspot.example.com");
      wifiEnterpriseConfig.setRealm("hotspot.example.com");
      wifiEnterpriseConfig.setEapMethod(WifiEnterpriseConfig.Eap.TTLS);
      wifiEnterpriseConfig.setPhase2Method(WifiEnterpriseConfig.Phase2.MSCHAPV2);
      wifiEnterpriseConfig.setIdentity("example");
      wifiEnterpriseConfig.setPassword("example");
      wifiEnterpriseConfig.setCaCertificate(cert); // getting cert part is omitted

      WifiConfiguration wifiConfiguration = new WifiConfiguration();
      wifiConfiguration.FQDN = "hotspot.example.com";
      wifiConfiguration.providerFriendlyName = "hotspot.example.com";
      wifiConfiguration.roamingConsortiumIds = new long[]111111;
      wifiConfiguration.enterpriseConfig = wifiEnterpriseConfig;

      int netId = wifiManager.addNetwork(wifiConfiguration);
      wifiManager.enableNetwork(netId, true);



      Device is trying to connect to Wi-Fi but fails on the ssl Radius server certificate verification stage with the following error:



      2019-03-05 16:52:30.718 22634-22634/? W/wpa_supplicant: TLS: Certificate verification failed, error 2 (unable to get issuer certificate) depth 1 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018'
      2019-03-05 16:52:30.718 22634-22634/? I/wpa_supplicant: wlan0: CTRL-EVENT-EAP-TLS-CERT-ERROR reason=1 depth=1 subject='/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018' err='unable to get issuer certificate'


      Our Radius server has certificate which is signed by an Intermediate certificate. The Intermediate certificate is signed by a Root certificate which is trusted in the system (double checked it). So we specify the Intermediate certificate using method wifiEnterpriseConfig.setCaCertificate. Do we do it right, or we miss something?



      Why do the we have to set some certificate manually at all? Why does the redius server can't be verified simply by the system root certs?



      Does anyone know why the problem occurs and how to solve it? Any advices are welcome!










      share|improve this question














      We are trying to configure Hotspot 2.0 Wi-fi connection using our app.
      This is how creating a Passpoint EAP-TTLS credentials looks like:



      WifiEnterpriseConfig wifiEnterpriseConfig = new WifiEnterpriseConfig();
      wifiEnterpriseConfig.setDomainSuffixMatch("hotspot.example.com");
      wifiEnterpriseConfig.setRealm("hotspot.example.com");
      wifiEnterpriseConfig.setEapMethod(WifiEnterpriseConfig.Eap.TTLS);
      wifiEnterpriseConfig.setPhase2Method(WifiEnterpriseConfig.Phase2.MSCHAPV2);
      wifiEnterpriseConfig.setIdentity("example");
      wifiEnterpriseConfig.setPassword("example");
      wifiEnterpriseConfig.setCaCertificate(cert); // getting cert part is omitted

      WifiConfiguration wifiConfiguration = new WifiConfiguration();
      wifiConfiguration.FQDN = "hotspot.example.com";
      wifiConfiguration.providerFriendlyName = "hotspot.example.com";
      wifiConfiguration.roamingConsortiumIds = new long[]111111;
      wifiConfiguration.enterpriseConfig = wifiEnterpriseConfig;

      int netId = wifiManager.addNetwork(wifiConfiguration);
      wifiManager.enableNetwork(netId, true);



      Device is trying to connect to Wi-Fi but fails on the ssl Radius server certificate verification stage with the following error:



      2019-03-05 16:52:30.718 22634-22634/? W/wpa_supplicant: TLS: Certificate verification failed, error 2 (unable to get issuer certificate) depth 1 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018'
      2019-03-05 16:52:30.718 22634-22634/? I/wpa_supplicant: wlan0: CTRL-EVENT-EAP-TLS-CERT-ERROR reason=1 depth=1 subject='/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=Thawte RSA CA 2018' err='unable to get issuer certificate'


      Our Radius server has certificate which is signed by an Intermediate certificate. The Intermediate certificate is signed by a Root certificate which is trusted in the system (double checked it). So we specify the Intermediate certificate using method wifiEnterpriseConfig.setCaCertificate. Do we do it right, or we miss something?



      Why do the we have to set some certificate manually at all? Why does the redius server can't be verified simply by the system root certs?



      Does anyone know why the problem occurs and how to solve it? Any advices are welcome!







      android ssl wifi android-wifi hotspot






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 7 at 9:11









      KirillKirill

      365215




      365215






















          0






          active

          oldest

          votes











          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55039959%2fhotspot-2-0-wi-fi-connection-radius-ssl-handshake-error%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55039959%2fhotspot-2-0-wi-fi-connection-radius-ssl-handshake-error%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Save data to MySQL database using ExtJS and PHP [closed]2019 Community Moderator ElectionHow can I prevent SQL injection in PHP?Which MySQL data type to use for storing boolean valuesPHP: Delete an element from an arrayHow do I connect to a MySQL Database in Python?Should I use the datetime or timestamp data type in MySQL?How to get a list of MySQL user accountsHow Do You Parse and Process HTML/XML in PHP?Reference — What does this symbol mean in PHP?How does PHP 'foreach' actually work?Why shouldn't I use mysql_* functions in PHP?

          Compiling GNU Global with universal-ctags support Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern) Data science time! April 2019 and salary with experience The Ask Question Wizard is Live!Tags for Emacs: Relationship between etags, ebrowse, cscope, GNU Global and exuberant ctagsVim and Ctags tips and trickscscope or ctags why choose one over the other?scons and ctagsctags cannot open option file “.ctags”Adding tag scopes in universal-ctagsShould I use Universal-ctags?Universal ctags on WindowsHow do I install GNU Global with universal ctags support using Homebrew?Universal ctags with emacsHow to highlight ctags generated by Universal Ctags in Vim?

          Add ONERROR event to image from jsp tldHow to add an image to a JPanel?Saving image from PHP URLHTML img scalingCheck if an image is loaded (no errors) with jQueryHow to force an <img> to take up width, even if the image is not loadedHow do I populate hidden form field with a value set in Spring ControllerStyling Raw elements Generated from JSP tagds with Jquery MobileLimit resizing of images with explicitly set width and height attributeserror TLD use in a jsp fileJsp tld files cannot be resolved