CA Certificate Do not Validate OnePlus 8 - OnePlus 8 Questions & Answers

Hi,
does anyone encountered loosing the wifi connection for the Peap Method and MSCHAPv2 for the Phase 2 authentication?
How to resolve this concern. im not sure if google removed for good the "do not validate option for the CA Certificate or do we have a workaround for this? thanks

kimimaru23 said:
Hi,
does anyone encountered loosing the wifi connection for the Peap Method and MSCHAPv2 for the Phase 2 authentication?
How to resolve this concern. im not sure if google removed for good the "do not validate option for the CA Certificate or do we have a workaround for this? thanks
Click to expand...
Click to collapse
There are a couple of Q&A's regarding this matter here and here.

thanks. i tried all thier suggestion but non of them worked out.

Related

Cannot connect to 802.1x PEAP MSCHAPv2 network

I cannot connect my AT&T Fuze to my work wireless network. This network requires the following settings:
Network Authentication: Open
Data Encryption: WEP (key is automatically provided)
Authentication: 802.1x Protected EAP (PEAP)
Inner Authentication: Secured password (EAP-MSCHAP v2)
Problem #1 - When I add the wireless network to the Wi-Fi settings, I select EAP type as "PEAP." I try to press the <Properties> button to set the inner authentication to MSCHAPv2, but receive an error message "Cannot log on to the network. This network requires a personal certificate to positively identify you." However this network does not require personal certificates.
Problem #2 - So I ignore that and press <Finish>. I am prompted for my credentials (username/password/domain). I enter them and press <OK>. No good. I am then repeatedly prompted for my credentials. [UPDATE: I just tried it for the 53rd time and just this once I was able to magically connect.]
I have read through many posts of similar complaints. I disabled server certification validatin by adding the ValidateServerCert value to the HKLM\Comm\EAP\Extension\25 key even though I have successfully installed the appropriate root certificate on the device. I also added the ValidateServerCert value to the \26 key just in case. I also set the wireless power mode to Best Performance.
What makes this particularly annoying is that I configured a coworkers iPhone to connect to the network. It was a giant pain because I had to install some sort of enterprise configuration software on a server and email her a mobile configuration profile from this application. Well the joke is on me because my WM6.1 phone cannot even connect.
Advice on what to do next? Thanks for your assistance.
I have the exact same problem... anybody found some sort of solution?
In case you still have the problem:
http://www.securew2.org/
Their program helped me overcome my issues with peap. Hope it works for you too
(taken from http://forum.xda-developers.com/showthread.php?t=284534&page=2 )
Thanks! Just how i tried - and too workng!
In case you still have the problem:
http://www.securew2.org/
Their program helped me overcome my issues with peap. Hope it works for you too
Click to expand...
Click to collapse
I am the OP. I was looking at SecureW2 as a last resort, as I am generally opposed to installing 3rd party applications to perform what should be core OS functions. Too many potential issues down the road. Fortunately I overcame my problem #2 stated above. On a separate post, somebody captured network traffic and determined that credential request/response was getting out of sync b/c the access point was not allowing enough time to respond. So after entering credentials and checking the "Save" box, I just banged away on the <OK> button as fast as possible. Eventually I connected. At this point the credentials are cached so I immediately connect from then on. I have tried this on two different HTC Fuze devices to my company's 802.1x PEAP MSCHAPv2 wireless network and it works great.
I also verified that since I installed the proper root certificate on my Fuze, I do not need to disable certificate validation by changing the ValidateServerCert registry value.
So the Windows Mobile 6.1 networking has two problems that will hopefully be fixed in a future update to make this easier for everyone.
So all you do is hit the OK button as fast as possible?
just making short login ans password
So all you do is hit the OK button as fast as possible?
Click to expand...
Click to collapse
Yes if you are experiencing problem #2 in the original post, repeated login prompts even though you know the credentials are correct.
just making short login ans password
Click to expand...
Click to collapse
The length of the username and password do not matter. And most credentials used with corporate networks are subject to complexity rules so cannot be arbitrarily short.
I found another solution, well the It guys from my Uni did.
Apparently you just have to increase the Wifi power setting to max. Otherweise the phone cannot process the peap crypto processes as it is limited by power saving mode.
http://social.microsoft.com/Forums/en-US/windowsmobile/thread/101f89b3-87fc-4cef-ac92-ece1aca9c12f/
i have the same problem. i dont understand how you overcame it
as0r: Changing the wifi power setting did not resolve problem #2 described in my original post, repeated login prompts.
jvar11889: How far did you make it, are you experiencing at problem #2 described in my original post, repeated login prompts? Is your required wifi configuration the same (802.1x PEAP MSCHAPv2)? I have succeeded on two different Fuzes, multiple times.
as0r said:
I have the exact same problem... anybody found some sort of solution?
In case you still have the problem:
http://www.securew2.org/
Their program helped me overcome my issues with peap. Hope it works for you too
(taken from http://forum.xda-developers.com/showthread.php?t=284534&page=2 )
Click to expand...
Click to collapse
I used this solution and worked for me!
Tried all the other tips mentioned, like for example the "power trick", without any luck!
However i have just flashed my TP from stock norwegian ROM to ROMeOS, dont know if this had any influence, but sercurew2 did the trick!
Its not really a 3rd party software, more like and integration into windows mobile!
Follow the instalations and setup guide from the site!
And Thanks for posting this, i have tried to get it working for more than 2 weeks now
Its not really a 3rd party software, more like and integration into windows mobile!
Click to expand...
Click to collapse
I disagree because the release notes clearly list the DLL's installed on your device. There is nothing inherently wrong with 3rd party software; I just like to reduce complexity by only installing additional software when I can't get what I want using the buillt-in features. If this was the only way I could connect to my 802.1x network, I would certainly install it.
I'm glad you are up and running. I have a hard time believing Microsoft is not aware of these problems. If they are serious about WM competing with iPhone and Android, Microsoft needs to jump on top of problems like this.
rlsmith999 said:
I disagree because the release notes clearly list the DLL's installed on your device. There is nothing inherently wrong with 3rd party software; I just like to reduce complexity by only installing additional software when I can't get what I want using the buillt-in features. If this was the only way I could connect to my 802.1x network, I would certainly install it.
I'm glad you are up and running. I have a hard time believing Microsoft is not aware of these problems. If they are serious about WM competing with iPhone and Android, Microsoft needs to jump on top of problems like this.
Click to expand...
Click to collapse
I agree with you! MS should do something about this! However, i talked to the EU HTC Support team, and they said a new ROM / Fimrware is due to be released end of February! Maybe there will be some kind of fix to this problem? Have heard that the HTC TP have some kind of problems installing certificates or something like that (havent read this myself, just heared it from someone working in a Cell Phone shop).
Hope you'll post here if you find a better solution!
Good luck!
zemlol said:
I used this solution and worked for me!
Tried all the other tips mentioned, like for example the "power trick", without any luck!
However i have just flashed my TP from stock norwegian ROM to ROMeOS, dont know if this had any influence, but sercurew2 did the trick!
Its not really a 3rd party software, more like and integration into windows mobile!
Follow the instalations and setup guide from the site!
And Thanks for posting this, i have tried to get it working for more than 2 weeks now
Click to expand...
Click to collapse
I am glad it helped you, but it stopped working for me a couple of days ago. Would you mind posting your config?
Cheers
Try and go into the securew2 settings tab !
And check for "prompt for username and password" ?
It switches on and off sometimes!
What config info you want?
hi boys...
i have the same problem... I cant connect to wifi of my university because his used a protocol that not compatible of andoid...
this is the guide of my University for linux sistem...
Sicurezza wireless: WPA e WPA2 Enterprise
Autenticazione: EAP Protetto (PEAP)
Identita anonima : anonymous
Certificato della CA: (Nessuno)
Versione PEAP: Versione 0
Autenticazione interna: MSCHAPv2
utente : il proprio indirizzo di mail studenti (esempio [email protected])
Password: ( la password del servizio wifi inserita in fase di attivazione)
now the problem is that my liquid ask me only password, and only for this not possible to connect.
anyway help me...
Same here
i have the same issue as well. i have tried all kinds of solutions. adding the reg key, securw2, advanced config tool and many more but nothing has worked. i even flashed a new 6.5 rom and that didnt work either. my fellow techs have i-phones and they find this pretty funny so i would love to get it to work. I like htc and dont really want to go to iphone so hopefully someone out there has the solution that works.

vpn issue -server hungup

Is anyone having problem connecting to vpn with transformer? My iphone can connect on the same wifi network, so it may not be the firewall or port forward issue. Any clue? Getting error -server hungup.
golam1 said:
Is anyone having problem connecting to vpn with transformer? My iphone can connect on the same wifi network, so it may not be the firewall or port forward issue. Any clue? Getting error -server hungup.
Click to expand...
Click to collapse
I have several PPTP connections setup and working on my Transformer. In order for people here to help, you'll probably need to provide more details:
What type of VPN connection is giving you trouble? PPTP, L2TP, IPSEC?
What type of firewall or device are you trying to connect to? SonicWall, Watchguard, pfSense, etc
What is the verbatim error message you are getting? is it really just "server hungup"?
Can you provide any log files from the VPN server that you are trying to connect to that shows where the failure is?
I've tried both on PPTP and L2TP. The exact wording of the error message is 'Server hung up. The username and password you entered could be incorrect'. The same configuration works on my iphone and 2 other computers on the same wifi network.
Unfortunately, without being able to see log files from the device you are trying to connect to I could only make a wild guess as to what is happening.
The problem I find most frequently with PPTP connections is comming up with a combination of authentication and encryption protocols that are supported on both the client and host.
The only thing I could suggest would be to try changing some of the encryption options at both ends of the connection and see what happens.
Android dosen't support MSCHAP on PPTP, said in a different way, dosen't support encryption. Also it's a very recent issue, it's been there only since 1.6
Get encryption disabled on the server and everything will be alright. Lol.
(sarcasm: VPN support has been added in 1.6)
Sent from my GT-P1000 using Tapatalk
i already tried disabling encryption...didn't work. How do I get the log? Sorry if I sound novice.
golam1 said:
i already tried disabling encryption...didn't work. How do I get the log? Sorry if I sound novice.
Click to expand...
Click to collapse
Disabled on Android or on the server? On Android only it's pointless
Sent from my GT-P1000 using Tapatalk
I use VPN L2PT every day @ starbucks
No Issues
Sent from my Transformer TF101 using xda premium
I use pptp vpn for iphone connectivity it is good and fast
"server hungup" means you have a bad username/password combo
is there a way to clear just the network settings like iphone in Honeycomb without loosing the data?

vpn / ics

Ok, maybe it is not related to ics. After installing ics, I lost my vnp connection for the office (maybe because I was not using any lock screen before) I have re-entered my vpn, but now I always get a "timeout" when I try to connect Do any of you who are using vpn's connection also have this issues, or maybe I have something wrong in my vpn settings ?
Anyone with stock firmware ics can confirm vpn is still working ?
Working fine for me, might be your specific vpn?
Sent from my Transformer TF101 using xda premium
Ok thanks. I'll make sure with the technicien here that everything is ok on their side
I had the same problem...the vpn connection settings were erased after ics update.
I created the connection one more time but didn't worked. I deleted that connection also and created another one...with the same details and worked.
Can confirm this issue also. After creating a new connection vpn works like a charm.
L2TP/IPSec PSK vpn is broken for me after upgrade to ICS. Seems to be a known problem with ICS. My colleague's Transformer Prime with ICS also not working with same type of VPN. It was working great with Honeycomb 3.2.1 before upgrade on both devices. I use the tablet for work extensively so this kind of sucks. Everything else is great.
Have a B90 TF101 so can't easily downgrade!
So is it an accurate assessment that L2 VPNs still do not work on ICS, such as solutions from Cisco and Juniper? We had to setup a special L2TP/IPSec PSK for just Android devices, whereas iDevices work just fine with industry standard SSL VPNs. Amazing that Google can't get on board with this. Wondering too if the Exchange cert issues still persist with the default mail client.
Yes. We setup L2TP/IPSec with PSK on a SonicWall firewall that works for both the iDevices and our Android devices. All android devices that upgraded to ICS stopped working. Will try to connect but will timeout trying to establish connection. I can't confirm all other L2TP VPN types but PSK is definitely not functioning.
We've never had any issues with Exchange push on the devices.
I can confirm it.
Today we have tested furthermore.
Everything is ok on the server side and on the client side.
Looking at the firewall, we can see the tf101 establishing a connection, but nothing about phase 2, it's like the server is giving the acknowledge about the PSK, but the TF101 can't hear or is not listening to it.. eventually it goes out with a timeout.
Everything was ok before ics.
where should i post this message, is it enough to be listed here or should a send a support mail to asus ? or google ?
by the way I've tried deleting and recreating, but still not working.
I formatted before and after ics. I would suggest a format first.
Sent from my GT-I9100 using xda premium
is there a solusion for not using a secure lock while using vpn on ics?
Sent from my HTC Sensation Z710e using xda premium
I've done a factory reset too, still the same problem
Alternative Solution
Hello,
This isnt a fix by any means but have you had a look at 2X Application XG Server, it is a little like citrix but a hell of a lot cheaper.
The client is awesome and works perfectly for windows, android and iOS.
It is free if you have a low count of concurrent users, I believe it is 5 concurrent users for free, anyway the link is below;
cant post links guys sorry it is 2x with www and .com in between...
If you need a hand with deployment drop me an email at [email protected] and we can sort something out, not doing the big sell here guys just something we use as a company when we decided to move our customers away from VPN's.
Anyway hope someone finds it useful.
cheers.
Don't know if this will help but i use vpnc widget and 2x client. My system is all cisco, and the only way i could get to it before was with an ipad, which i have since given away for obvious reasons. I have been on revolver for some time now, and just upgraded to 4, with no issues whatsoever - if anything it is more stable!
Works for me, too, but I sure would like to know if anyone has figured out how to disable the screen-lock when credential storage is enabled, as I am using mine for an individual OpenVPN and PPTP vpn and it is just plain irritating.
i've sent technical inquiries to Asus with no response. Very disappointing. I guess they are fixing other issues that have a more broad base of users before they take on things like VPN. I believe this is a general ICS issue as a quick search on Google shows varies reports across different manufacturers who have released ICS and the L2TP VPNs are broken. Several bug reports have been reported to Google. Great way for Google to alienate business users.
Do a Google search with these terms and you see all the references to this problem
"L2TP IPSEC PSK android ics"
I was wondering if anyone out there was using an IPSec Xauth PSK type connection? This is what we have at work. I set up the connection on my TF101, I put in all the correct info, and when I clicked connect it connected; however, there was no data sent or received. I disconnect and try reconnecting, but the connection times out. Before the ICS update I didn't even have this connection option so its a step in the right direction, the only problem is that nothing happens when I connect. Is anyone else having the same problem? Is this a known issue? Thanks in advance for any help you can offer.
x_kain_x said:
I was wondering if anyone out there was using an IPSec Xauth PSK type connection? This is what we have at work. I set up the connection on my TF101, I put in all the correct info, and when I clicked connect it connected; however, there was no data sent or received. I disconnect and try reconnecting, but the connection times out. Before the ICS update I didn't even have this connection option so its a step in the right direction, the only problem is that nothing happens when I connect. Is anyone else having the same problem? Is this a known issue? Thanks in advance for any help you can offer.
Click to expand...
Click to collapse
Works great here. I use the vpnc widget and x2 client as well works a treat since ics update.
vettejock99 said:
Works for me, too, but I sure would like to know if anyone has figured out how to disable the screen-lock when credential storage is enabled, as I am using mine for an individual OpenVPN and PPTP vpn and it is just plain irritating.
Click to expand...
Click to collapse
Grrr... indeed. But I've foud a free app on Market: VpnROOT - PPTP - Manager
karlr30 said:
I've done a factory reset too, still the same problem
Click to expand...
Click to collapse
+1
Edit: Hummm... for me I've found a temporary solution by using another app found on Market: "VpnROOT - PPTP - Manager".
My VPN use PPTP with MPPE encryption so, this one works fine for me.

[Q] Razr HD with wifi problem

Hi, I found my Razr HD has a problem with WPA2 Enterprise. I exchanged for a new one today but the same issue.
In modify network, the phase2 authentication can never be saved, while my university wifi requires MSCHAPV2. So there is no way I could connect to it.
Is there anyone having the same issue? and have you solved it?
Thanks!
avenxyc said:
Hi, I found my Razr HD has a problem with WPA2 Enterprise. I exchanged for a new one today but the same issue.
In modify network, the phase2 authentication can never be saved, while my university wifi requires MSCHAPV2. So there is no way I could connect to it.
Is there anyone having the same issue? and have you solved it?
Thanks!
Click to expand...
Click to collapse
I too had the same issue. Seems like there's a bug with MSCHAPV2 setting (it gets reset every time you exit the settings panel). Solved it by downloading a 3rd party app.It's called "Wifi Manager" by Kostya Vasilyev.
Use this one to configure your WiFi connection. Worked like a charm for me.
I believe that has been documented on the moto forums already
majidp said:
I too had the same issue. Seems like there's a bug with MSCHAPV2 setting (it gets reset every time you exit the settings panel). Solved it by downloading a 3rd party app.It's called "Wifi Manager" by Kostya Vasilyev.
Use this one to configure your WiFi connection. Worked like a charm for me.
Click to expand...
Click to collapse
Thanks!! I will see if it works!
syntrix said:
I believe that has been documented on the moto forums already
Click to expand...
Click to collapse
I found my old droid 2 Global has the same issue, it doesn't save the phase 2 setting as well. But it does get connected! just don't know why.

Statically setting my IP address to one on a different subnet causes the connection to cycle repeatedly

For example,
The WiFi connects with no internet, DHCP address of 192.168.2.2 provided. I then manually change phone's IP address to 192.168.1.2 to access devices on a 1. subnet. The result? My connection repeatedly cycles. Traffic does briefly pass through but the cycling makes it unworkable.
My only workaround is to set DHCP on the router to the subnet I need to be on. If anyone's curious, this is just to configure Ubiquiti radios and to occasionally access backhaul equipment. I like being free of a laptop whenever possible.
I've tried tinkering with every modem related setting I can find to no avail. I'd like to grab proper logs but the app I got wasn't very helpful. This is a bit out of my wheelhouse unfortunately.
Has anyone dealt with this and found a solution? This is on a Pixel 7. Never had this problem on my S22.
I hope someone can help. Thanks!
Hi there. We've recently faced the same issue, so I'd like to know if you've solved it.
Hey there, thanks for sharing your experience with this issue. I can definitely understand how frustrating it can be when things don't work as expected. It sounds like you've tried a few different things already, but have you checked out https://routeripnet.com/ip/192-168-8-1/ for any troubleshooting tips or solutions? It might be worth taking a look to see if anything there can help. It's also possible that there's an issue with the app you're using. Maybe try a different one to see if that helps. Good luck, and let us know if you find a solution that works for you!
JordinMaddox said:
Hi there. We've recently faced the same issue, so I'd like to know if you've solved it.
Click to expand...
Click to collapse
I haven't. Have you?
krsmas said:
I haven't. Have you?
Click to expand...
Click to collapse
266885171
I reported to Google's issue tracker. I suggest you do the same.

Categories

Resources