From 6c9323e3a8b6e4982d101de42327311439a5ff09 Mon Sep 17 00:00:00 2001 From: Josh Drake Date: Mon, 5 Oct 2026 13:30:28 -0500 Subject: [PATCH 1/6] Wireless guide: draft iOS and Android with Workspace ONE UEM (SCEP) Add an MDM-managed client section for iOS and Android devices managed by Workspace ONE UEM, using the Smallstep integration's dynamic-challenge SCEP CA resource, a request template, and per-platform Wi-Fi profiles. Call out that these certificates come from the team's Agents authority, which the RADIUS server must trust. Add APNs to the Vale vocabulary. --- .../config/vocabularies/Smallstep/accept.txt | 1 + tutorials/protect-wireless-networks.mdx | 139 ++++++++++++++++++ 2 files changed, 140 insertions(+) diff --git a/.vale/styles/config/vocabularies/Smallstep/accept.txt b/.vale/styles/config/vocabularies/Smallstep/accept.txt index 77f561c7..b65a95d3 100644 --- a/.vale/styles/config/vocabularies/Smallstep/accept.txt +++ b/.vale/styles/config/vocabularies/Smallstep/accept.txt @@ -952,3 +952,4 @@ publicKey serialNumber testuser disallow +APNs diff --git a/tutorials/protect-wireless-networks.mdx b/tutorials/protect-wireless-networks.mdx index 990321bc..64b259c5 100644 --- a/tutorials/protect-wireless-networks.mdx +++ b/tutorials/protect-wireless-networks.mdx @@ -199,6 +199,8 @@ You provide: - **`nasIPs`**: the public (WAN) IP addresses your access points or wireless controllers will send RADIUS traffic from. This is how the service attributes incoming requests to your team, so each IP must be unique across Smallstep customers. - **`clientCA`**: the CA bundle the RADIUS server will trust to verify clients—the authority root you saved in Step 1. + If Workspace ONE UEM issues certificates to iOS or Android devices, include your team's Agents authority root as well + (see [iOS and Android with Workspace ONE UEM](#ios-and-android-with-workspace-one-uem-scep)). ```bash jq -n --rawfile ca client_ca.crt \ @@ -357,6 +359,7 @@ The subsections below cover the common combinations: - [macOS and iOS with Jamf Pro (SCEP)](#macos-and-ios-with-jamf-pro-scep) - [macOS with Jamf Pro (ACME Device Attestation)](#macos-with-jamf-pro-acme-device-attestation) - [macOS with Workspace ONE UEM](#macos-with-workspace-one-uem) +- [iOS and Android with Workspace ONE UEM (SCEP)](#ios-and-android-with-workspace-one-uem-scep) - [Windows with Intune (SCEP)](#windows-with-intune-scep) - [Windows with Intune (agent credential + OMA-URI profile)](#windows-with-intune-agent-credential--oma-uri-profile) - [Windows with Workspace ONE UEM](#windows-with-workspace-one-uem) @@ -542,6 +545,142 @@ In Workspace ONE UEM: Enrolled devices in the assigned groups will receive the profile and be ready to join the network. +### iOS and Android with Workspace ONE UEM (SCEP) + +In this workflow, Workspace ONE UEM deploys a profile that gets a client certificate from Smallstep's SCEP server, +installs the RADIUS server CA, and configures the Wi-Fi network. +Workspace ONE fetches a single-use SCEP challenge from Smallstep for each device, so no shared secret is embedded in the profile. +The Smallstep Agent is not required on the device. + +#### Before you begin + +You will need: + +- Workspace ONE UEM [connected to Smallstep](./connect-workspace-one-to-smallstep.mdx) (steps 1 and 2 of that guide). + Keep the SCEP URL, SCEP Challenge URL, and challenge username and password from your + [Workspace ONE integration settings](https://smallstep.com/app/?next=/settings/devices) handy. +- For iOS and iPadOS: a valid Apple Push Notification service (APNs) certificate in Workspace ONE + (**Groups & Settings → All Settings → Devices & Users → Apple → APNs For MDM**), and a test device enrolled in Workspace ONE. +- For Android: Workspace ONE registered as your Android Enterprise EMM + (**Groups & Settings → All Settings → Devices & Users → Android → Android EMM Registration**), + and a test device enrolled with a work profile or as a fully managed device. + The device must have a screen lock set, or Android won't install the client certificate. +- Your RADIUS server details: the CA certificate that issued your RADIUS server's certificate, + and the name on that certificate. + For Smallstep Managed RADIUS, these are the `serverCA` and `serverHostname` from [Step 2](#step-2-configure-the-enforcement-point) + (the [Smallstep RADIUS Root CA](https://dl.smallstep.com/radius.smallstep.com-root.crt) and `radius.smallstep.com`). + +#### Trust the Agents authority on your RADIUS server + +Certificates that Workspace ONE requests through the Smallstep integration are issued by your team's **Agents** authority +(`agents.[your team].ca.smallstep.com`), not by the authority behind a credential you created in Step 1. +Your RADIUS server must trust it: + +1. In the Smallstep dashboard, go to [Settings → Device Management](https://smallstep.com/app/?next=/settings/devices), + choose **Manage** on the Omnissa Workspace ONE integration, and open the **Settings** tab. +2. Under **Authority Certificates**, choose **Download Root**. +3. Add that root to your RADIUS server's trusted client CA bundle. + For Smallstep Managed RADIUS, append it to the `clientCA` with the + [Put Managed RADIUS](https://gateway.smallstep.com/v2025-01-01/operations/PutManagedRadius) endpoint. + The request body must include `name`, `nasIPs`, and the full `clientCA` bundle, so send back the existing values with the new root appended. + +#### Add a Workspace ONE CA resource + +If you already added a Smallstep CA resource and request template while following +[Connect Workspace ONE UEM to Smallstep](./connect-workspace-one-to-smallstep.mdx), you can reuse them and skip to [Create the iOS profile](#create-the-ios-profile). + +For compatibility with Workspace ONE, Smallstep emulates a Microsoft NDES server, including its dynamic challenges. + +1. In Workspace ONE UEM, go to **Resources → Certificates → Certificate Authorities** and choose **Add** +2. Fill out the form: + - **Name**: a descriptive name, for example `Smallstep` + - **Authority Type**: `Microsoft ADCS` + - **Protocol**: `SCEP` + - **Version**: `NDES 2008/2012` + - **SCEP URL**: the SCEP URL from your Smallstep integration settings + - **Challenge Type**: `Dynamic` + - **Challenge Username**, **Challenge Password**, and **Confirm Challenge Password**: the challenge username and password from Smallstep + - **SCEP Challenge URL**: the SCEP Challenge URL from Smallstep + - Select **Show Advanced Options**, and set **SCEP Challenge Length** to `32` + - Leave **Enable Proxy** disabled. Smallstep's SCEP server is reachable from the public internet. +3. Choose **Test Connection** and wait for a success message +4. Choose **Save and Add Template** + +#### Add a certificate request template + +1. Fill out the **Certificate Template** form: + - **Name**: for example, `Smallstep Wi-Fi` + - **Certificate Authority**: the CA resource you just added + - **Subject Name**: `CN={DeviceUuid}` + - **Private Key Length**: `2048` + - **Private Key Type**: select both **Signing** and **Encryption** + - **SAN Type**: choose **Add**, select **URL**, and enter `deviceid://{DeviceUuid}` + - **Automatic Certificate Renewal**: **Enabled**, with an **Auto Renewal Period (days)** of `5` + - **Publish Private Key**: **Disabled** +2. Choose **Save** + +Keep the `{DeviceUuid}` subject and SAN as shown. +Smallstep uses the Workspace ONE device UUID to link each certificate to the device in your inventory. + +#### Create the iOS profile + +1. In Workspace ONE UEM, go to **Resources → Profiles & Baselines → Profiles**, then choose **Add → Add Profile** +2. Select **Apple iOS**, leave **Management Type** set to **Imperative** and **Context** set to **Device**, and choose **Next** +3. Name the profile, for example **EAP-TLS Wi-Fi with Smallstep** +4. Add a **SCEP** payload: + - **Credential Source**: **Defined Certificate Authority** + - **Certificate Authority**: the Smallstep CA resource + - **Certificate Template**: the Smallstep template +5. Add a **Credentials** payload for the RADIUS server CA: + - **Credential Source**: **Upload** + - **Credential Name**: for example, `Smallstep RADIUS Root CA` + - **Certificate**: upload your RADIUS server CA certificate with **Choose File**, then choose **Attach Certificate** +6. Add a **Wi-Fi** payload: + - **Service Set Identifier**: your SSID + - **Auto-Join**: enabled + - **Security Type**: **WPA2 Enterprise** or **WPA3 Enterprise**, to match your network + - **Protocols**: select **EAP-TLS** + - **Identity Certificate**: **SCEP** + - **Trusted Certificates**: select **Credentials** (the RADIUS server CA) + - **Trusted Server Certificate Names**: the name on your RADIUS server's certificate, for example `radius.smallstep.com` + - **TLS Certificate Required**: enabled +7. Choose **Next**, select a **Smart Group** containing your test devices, and choose **Save & Publish** + +#### Create the Android profile + +1. In Workspace ONE UEM, go to **Resources → Profiles & Baselines → Profiles**, then choose **Add → Add Profile** +2. Select **Android** +3. Name the profile, for example **EAP-TLS Wi-Fi with Smallstep (Android)** +4. Add a **Credentials** payload for the client certificate (this becomes **Credentials 1**): + - **Credential Source**: **Defined Certificate Authority** + - **Certificate Authority**: the Smallstep CA resource + - **Certificate Template**: the Smallstep template +5. In the same payload, choose **+ ADD** to add **Credentials 2** for the RADIUS server CA: + - **Credential Source**: **Upload** + - **Certificate**: upload your RADIUS server CA certificate with **Choose File**, then choose **Attach Certificate** +6. Add a **Wi-Fi** payload: + - **Service Set Identifier**: your SSID + - **Security Type**: **WPA/WPA2 Enterprise** + - **SFA Type**: **TLS** + - **Identity**: `{DeviceUuid}` + - **Trusted Server Domain**: the name on your RADIUS server's certificate, for example `radius.smallstep.com` + - **Identity Certificate**: **Credentials 1** + - **Root Certificates**: **Credentials 2** +7. Choose **Next**, select a **Smart Group** containing your test devices, and choose **Save & Publish** + +Set both **Root Certificates** and **Trusted Server Domain**. +Current Android versions refuse to join an enterprise network that doesn't validate the RADIUS server. + +#### Verify + +When a device receives the profile, Workspace ONE requests a single-use challenge from Smallstep, +and the device enrolls for its certificate and joins the network without prompting. + +- In Workspace ONE, open the device's details. The **Profiles** tab shows the install status, and the **Certificates** tab shows the certificate issued by your Agents authority. +- On iOS, go to **Settings → General → VPN & Device Management**, open the Workspace ONE profile, and check for the SCEP certificate. +- If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your Agents authority root + (see [Trust the Agents authority on your RADIUS server](#trust-the-agents-authority-on-your-radius-server)). + ### Windows with Intune (SCEP) In this workflow, Intune deploys CA trust, a SCEP-issued client certificate, and the Wi-Fi profile. From 2f90e829c87c152dfba196a436166e8861c37d5a Mon Sep 17 00:00:00 2001 From: Josh Drake Date: Mon, 5 Oct 2026 14:32:37 -0500 Subject: [PATCH 2/6] Wireless guide: make the Workspace ONE mobile section RADIUS-agnostic Refer to "your RADIUS server's CA" and its certificate hostname instead of Smallstep Managed RADIUS values, and drop the Managed RADIUS API steps for adding the Agents root. Update Verify with what testing showed on iOS: the Audit log's certificate-issued event, the Workspace ONE event log sequence, and pushing a profile that stays pending. --- tutorials/protect-wireless-networks.mdx | 36 +++++++++++-------------- 1 file changed, 16 insertions(+), 20 deletions(-) diff --git a/tutorials/protect-wireless-networks.mdx b/tutorials/protect-wireless-networks.mdx index 64b259c5..afd505d8 100644 --- a/tutorials/protect-wireless-networks.mdx +++ b/tutorials/protect-wireless-networks.mdx @@ -199,8 +199,6 @@ You provide: - **`nasIPs`**: the public (WAN) IP addresses your access points or wireless controllers will send RADIUS traffic from. This is how the service attributes incoming requests to your team, so each IP must be unique across Smallstep customers. - **`clientCA`**: the CA bundle the RADIUS server will trust to verify clients—the authority root you saved in Step 1. - If Workspace ONE UEM issues certificates to iOS or Android devices, include your team's Agents authority root as well - (see [iOS and Android with Workspace ONE UEM](#ios-and-android-with-workspace-one-uem-scep)). ```bash jq -n --rawfile ca client_ca.crt \ @@ -548,7 +546,7 @@ Enrolled devices in the assigned groups will receive the profile and be ready to ### iOS and Android with Workspace ONE UEM (SCEP) In this workflow, Workspace ONE UEM deploys a profile that gets a client certificate from Smallstep's SCEP server, -installs the RADIUS server CA, and configures the Wi-Fi network. +trusts your RADIUS server's CA, and configures the Wi-Fi network. Workspace ONE fetches a single-use SCEP challenge from Smallstep for each device, so no shared secret is embedded in the profile. The Smallstep Agent is not required on the device. @@ -565,10 +563,8 @@ You will need: (**Groups & Settings → All Settings → Devices & Users → Android → Android EMM Registration**), and a test device enrolled with a work profile or as a fully managed device. The device must have a screen lock set, or Android won't install the client certificate. -- Your RADIUS server details: the CA certificate that issued your RADIUS server's certificate, - and the name on that certificate. - For Smallstep Managed RADIUS, these are the `serverCA` and `serverHostname` from [Step 2](#step-2-configure-the-enforcement-point) - (the [Smallstep RADIUS Root CA](https://dl.smallstep.com/radius.smallstep.com-root.crt) and `radius.smallstep.com`). +- Your RADIUS server's CA certificate, and the hostname on your RADIUS server's certificate + (see [Step 2](#step-2-configure-the-enforcement-point)). #### Trust the Agents authority on your RADIUS server @@ -579,10 +575,7 @@ Your RADIUS server must trust it: 1. In the Smallstep dashboard, go to [Settings → Device Management](https://smallstep.com/app/?next=/settings/devices), choose **Manage** on the Omnissa Workspace ONE integration, and open the **Settings** tab. 2. Under **Authority Certificates**, choose **Download Root**. -3. Add that root to your RADIUS server's trusted client CA bundle. - For Smallstep Managed RADIUS, append it to the `clientCA` with the - [Put Managed RADIUS](https://gateway.smallstep.com/v2025-01-01/operations/PutManagedRadius) endpoint. - The request body must include `name`, `nasIPs`, and the full `clientCA` bundle, so send back the existing values with the new root appended. +3. Add that root to the CAs your RADIUS server trusts for client certificates. #### Add a Workspace ONE CA resource @@ -631,18 +624,18 @@ Smallstep uses the Workspace ONE device UUID to link each certificate to the dev - **Credential Source**: **Defined Certificate Authority** - **Certificate Authority**: the Smallstep CA resource - **Certificate Template**: the Smallstep template -5. Add a **Credentials** payload for the RADIUS server CA: +5. Add a **Credentials** payload to trust your RADIUS server's CA: - **Credential Source**: **Upload** - - **Credential Name**: for example, `Smallstep RADIUS Root CA` - - **Certificate**: upload your RADIUS server CA certificate with **Choose File**, then choose **Attach Certificate** + - **Credential Name**: for example, `RADIUS Server CA` + - **Certificate**: upload your RADIUS server's CA certificate with **Choose File**, then choose **Attach Certificate** 6. Add a **Wi-Fi** payload: - **Service Set Identifier**: your SSID - **Auto-Join**: enabled - **Security Type**: **WPA2 Enterprise** or **WPA3 Enterprise**, to match your network - **Protocols**: select **EAP-TLS** - **Identity Certificate**: **SCEP** - - **Trusted Certificates**: select **Credentials** (the RADIUS server CA) - - **Trusted Server Certificate Names**: the name on your RADIUS server's certificate, for example `radius.smallstep.com` + - **Trusted Certificates**: select **Credentials** (your RADIUS server's CA) + - **Trusted Server Certificate Names**: the hostname on your RADIUS server's certificate - **TLS Certificate Required**: enabled 7. Choose **Next**, select a **Smart Group** containing your test devices, and choose **Save & Publish** @@ -655,15 +648,15 @@ Smallstep uses the Workspace ONE device UUID to link each certificate to the dev - **Credential Source**: **Defined Certificate Authority** - **Certificate Authority**: the Smallstep CA resource - **Certificate Template**: the Smallstep template -5. In the same payload, choose **+ ADD** to add **Credentials 2** for the RADIUS server CA: +5. In the same payload, choose **+ ADD** to add **Credentials 2**, which trusts your RADIUS server's CA: - **Credential Source**: **Upload** - - **Certificate**: upload your RADIUS server CA certificate with **Choose File**, then choose **Attach Certificate** + - **Certificate**: upload your RADIUS server's CA certificate with **Choose File**, then choose **Attach Certificate** 6. Add a **Wi-Fi** payload: - **Service Set Identifier**: your SSID - **Security Type**: **WPA/WPA2 Enterprise** - **SFA Type**: **TLS** - **Identity**: `{DeviceUuid}` - - **Trusted Server Domain**: the name on your RADIUS server's certificate, for example `radius.smallstep.com` + - **Trusted Server Domain**: the hostname on your RADIUS server's certificate - **Identity Certificate**: **Credentials 1** - **Root Certificates**: **Credentials 2** 7. Choose **Next**, select a **Smart Group** containing your test devices, and choose **Save & Publish** @@ -676,7 +669,10 @@ Current Android versions refuse to join an enterprise network that doesn't valid When a device receives the profile, Workspace ONE requests a single-use challenge from Smallstep, and the device enrolls for its certificate and joins the network without prompting. -- In Workspace ONE, open the device's details. The **Profiles** tab shows the install status, and the **Certificates** tab shows the certificate issued by your Agents authority. +- In the Smallstep dashboard, [Audit](https://smallstep.com/app/?next=/audit) shows an **X.509 certificate issued** event for each certificate. +- In Workspace ONE, open the device's details. The **Profiles** tab shows the install status, + and **More → Troubleshooting → Event Log** shows each step, from **Profiles Install Initialized** to **Profiles Install Processed**. +- If the profile stays pending, select it on the device's **Profiles** tab and choose **Install** to push it to the device. - On iOS, go to **Settings → General → VPN & Device Management**, open the Workspace ONE profile, and check for the SCEP certificate. - If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your Agents authority root (see [Trust the Agents authority on your RADIUS server](#trust-the-agents-authority-on-your-radius-server)). From dbec8211849cc68c00578d61f7b7e8d15060a15a Mon Sep 17 00:00:00 2001 From: Josh Drake Date: Mon, 5 Oct 2026 15:18:24 -0500 Subject: [PATCH 3/6] Wireless guide: Android findings from Workspace ONE testing Require Android Enterprise management (Work Profile or another Android Enterprise mode, not Android (Legacy)), note the Certificate Issued event Android logs, and add troubleshooting for devices that enroll in Hub's registered mode, adding a work profile to a device that's already set up, and paused work profiles. Bump updated_at. --- tutorials/protect-wireless-networks.mdx | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/tutorials/protect-wireless-networks.mdx b/tutorials/protect-wireless-networks.mdx index afd505d8..64cae8c1 100644 --- a/tutorials/protect-wireless-networks.mdx +++ b/tutorials/protect-wireless-networks.mdx @@ -1,5 +1,5 @@ --- -updated_at: September 02, 2026 +updated_at: October 05, 2026 title: Protect Wireless Networks with 802.1X EAP-TLS html_title: Protect Wireless Networks with 802.1X EAP-TLS Certificates and Smallstep description: Set up certificate-based Wi-Fi end to end. Issue client certificates via the Smallstep API, configure RADIUS and access points, and deploy to clients. @@ -561,7 +561,8 @@ You will need: (**Groups & Settings → All Settings → Devices & Users → Apple → APNs For MDM**), and a test device enrolled in Workspace ONE. - For Android: Workspace ONE registered as your Android Enterprise EMM (**Groups & Settings → All Settings → Devices & Users → Android → Android EMM Registration**), - and a test device enrolled with a work profile or as a fully managed device. + and a test device managed through Android Enterprise, with a work profile or as a fully managed device. + In the device's details in Workspace ONE, **Android Management** should show **Work Profile** (or another Android Enterprise mode), not **Android (Legacy)**. The device must have a screen lock set, or Android won't install the client certificate. - Your RADIUS server's CA certificate, and the hostname on your RADIUS server's certificate (see [Step 2](#step-2-configure-the-enforcement-point)). @@ -672,8 +673,16 @@ and the device enrolls for its certificate and joins the network without prompti - In the Smallstep dashboard, [Audit](https://smallstep.com/app/?next=/audit) shows an **X.509 certificate issued** event for each certificate. - In Workspace ONE, open the device's details. The **Profiles** tab shows the install status, and **More → Troubleshooting → Event Log** shows each step, from **Profiles Install Initialized** to **Profiles Install Processed**. + On Android, the log also shows **Certificate Issued** for your Smallstep CA resource. - If the profile stays pending, select it on the device's **Profiles** tab and choose **Install** to push it to the device. - On iOS, go to **Settings → General → VPN & Device Management**, open the Workspace ONE profile, and check for the SCEP certificate. +- If an Android device shows **Hub Registered** or **Android Management: Android (Legacy)**, it isn't managed through Android Enterprise and won't receive the profile. + Check that Android EMM registration is complete, and that + **Groups & Settings → All Settings → Devices & Users → General → Enrollment → Management Mode** + doesn't enroll Android devices without MDM management. Then re-enroll the device. +- To add a work profile to an Android device that's already set up, enroll it as employee-owned. + Corporate-owned Android Enterprise modes are provisioned during setup of a new or factory-reset device. +- If the work profile is paused (**Work apps** turned off on the device), the device won't check in or install profiles. - If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your Agents authority root (see [Trust the Agents authority on your RADIUS server](#trust-the-agents-authority-on-your-radius-server)). From d05b5b861ce5106b2a348e3b451c786add829810 Mon Sep 17 00:00:00 2001 From: Josh Drake Date: Mon, 5 Oct 2026 15:21:46 -0500 Subject: [PATCH 4/6] Wireless guide: tighten Workspace ONE template note and skip link State why the template uses the device UUID without claiming inventory linking that testing didn't confirm, and let readers who reuse an existing CA resource skip to either platform's profile. --- tutorials/protect-wireless-networks.mdx | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/tutorials/protect-wireless-networks.mdx b/tutorials/protect-wireless-networks.mdx index 64cae8c1..09226c27 100644 --- a/tutorials/protect-wireless-networks.mdx +++ b/tutorials/protect-wireless-networks.mdx @@ -581,7 +581,8 @@ Your RADIUS server must trust it: #### Add a Workspace ONE CA resource If you already added a Smallstep CA resource and request template while following -[Connect Workspace ONE UEM to Smallstep](./connect-workspace-one-to-smallstep.mdx), you can reuse them and skip to [Create the iOS profile](#create-the-ios-profile). +[Connect Workspace ONE UEM to Smallstep](./connect-workspace-one-to-smallstep.mdx), you can reuse them +and skip to creating the [iOS profile](#create-the-ios-profile) or the [Android profile](#create-the-android-profile). For compatibility with Workspace ONE, Smallstep emulates a Microsoft NDES server, including its dynamic challenges. @@ -613,8 +614,8 @@ For compatibility with Workspace ONE, Smallstep emulates a Microsoft NDES server - **Publish Private Key**: **Disabled** 2. Choose **Save** -Keep the `{DeviceUuid}` subject and SAN as shown. -Smallstep uses the Workspace ONE device UUID to link each certificate to the device in your inventory. +Keep the `{DeviceUuid}` subject and SAN as shown, +so Smallstep can associate each certificate with the Workspace ONE device that requested it. #### Create the iOS profile From c5590f98ef8098fc841c19ffec08cc80e99e2301 Mon Sep 17 00:00:00 2001 From: Josh Drake Date: Mon, 5 Oct 2026 15:29:39 -0500 Subject: [PATCH 5/6] Wireless guide: refer to the Workspace ONE issuing authority generically The integration's SCEP provisioner lives on the Agents authority by default, but Smallstep support can place it on another authority. Say "your issuing authority" and point readers to the integration settings to find its root, instead of naming the Agents authority. --- tutorials/protect-wireless-networks.mdx | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/tutorials/protect-wireless-networks.mdx b/tutorials/protect-wireless-networks.mdx index 09226c27..7c544c4e 100644 --- a/tutorials/protect-wireless-networks.mdx +++ b/tutorials/protect-wireless-networks.mdx @@ -567,15 +567,16 @@ You will need: - Your RADIUS server's CA certificate, and the hostname on your RADIUS server's certificate (see [Step 2](#step-2-configure-the-enforcement-point)). -#### Trust the Agents authority on your RADIUS server +#### Trust your issuing authority on your RADIUS server -Certificates that Workspace ONE requests through the Smallstep integration are issued by your team's **Agents** authority -(`agents.[your team].ca.smallstep.com`), not by the authority behind a credential you created in Step 1. -Your RADIUS server must trust it: +Certificates that Workspace ONE requests through the Smallstep integration are signed by your integration's issuing authority. +It may not be the authority behind a credential you created in Step 1, so make sure your RADIUS server trusts it. -1. In the Smallstep dashboard, go to [Settings → Device Management](https://smallstep.com/app/?next=/settings/devices), +Find your issuing authority in the Smallstep console: + +1. Go to [Settings → Device Management](https://smallstep.com/app/?next=/settings/devices), choose **Manage** on the Omnissa Workspace ONE integration, and open the **Settings** tab. -2. Under **Authority Certificates**, choose **Download Root**. +2. Under **Authority Certificates**, choose **Download Root** to get your issuing authority's root certificate. 3. Add that root to the CAs your RADIUS server trusts for client certificates. #### Add a Workspace ONE CA resource @@ -684,8 +685,8 @@ and the device enrolls for its certificate and joins the network without prompti - To add a work profile to an Android device that's already set up, enroll it as employee-owned. Corporate-owned Android Enterprise modes are provisioned during setup of a new or factory-reset device. - If the work profile is paused (**Work apps** turned off on the device), the device won't check in or install profiles. -- If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your Agents authority root - (see [Trust the Agents authority on your RADIUS server](#trust-the-agents-authority-on-your-radius-server)). +- If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your issuing authority's root + (see [Trust your issuing authority on your RADIUS server](#trust-your-issuing-authority-on-your-radius-server)). ### Windows with Intune (SCEP) From e62a2068c8cac19f8010aa9d71bf3f75a10dda50 Mon Sep 17 00:00:00 2001 From: Josh Drake Date: Mon, 5 Oct 2026 15:31:47 -0500 Subject: [PATCH 6/6] Wireless guide: plainer wording in the Workspace ONE mobile section Prefer active voice, merge the Android server-validation note into one sentence, and split the Verify list so troubleshooting has its own heading. --- tutorials/protect-wireless-networks.mdx | 43 +++++++++++++------------ 1 file changed, 23 insertions(+), 20 deletions(-) diff --git a/tutorials/protect-wireless-networks.mdx b/tutorials/protect-wireless-networks.mdx index 7c544c4e..2b36888c 100644 --- a/tutorials/protect-wireless-networks.mdx +++ b/tutorials/protect-wireless-networks.mdx @@ -547,8 +547,8 @@ Enrolled devices in the assigned groups will receive the profile and be ready to In this workflow, Workspace ONE UEM deploys a profile that gets a client certificate from Smallstep's SCEP server, trusts your RADIUS server's CA, and configures the Wi-Fi network. -Workspace ONE fetches a single-use SCEP challenge from Smallstep for each device, so no shared secret is embedded in the profile. -The Smallstep Agent is not required on the device. +Workspace ONE fetches a single-use SCEP challenge from Smallstep for each device, so the profile doesn't contain a shared secret. +You don't need the Smallstep Agent on the device. #### Before you begin @@ -561,16 +561,16 @@ You will need: (**Groups & Settings → All Settings → Devices & Users → Apple → APNs For MDM**), and a test device enrolled in Workspace ONE. - For Android: Workspace ONE registered as your Android Enterprise EMM (**Groups & Settings → All Settings → Devices & Users → Android → Android EMM Registration**), - and a test device managed through Android Enterprise, with a work profile or as a fully managed device. - In the device's details in Workspace ONE, **Android Management** should show **Work Profile** (or another Android Enterprise mode), not **Android (Legacy)**. - The device must have a screen lock set, or Android won't install the client certificate. + and a test device managed through Android Enterprise, either with a work profile or as a fully managed device. + In the device's details in Workspace ONE, **Android Management** should read **Work Profile** or another Android Enterprise mode, not **Android (Legacy)**. + Android won't install the client certificate unless the device has a screen lock. - Your RADIUS server's CA certificate, and the hostname on your RADIUS server's certificate (see [Step 2](#step-2-configure-the-enforcement-point)). #### Trust your issuing authority on your RADIUS server -Certificates that Workspace ONE requests through the Smallstep integration are signed by your integration's issuing authority. -It may not be the authority behind a credential you created in Step 1, so make sure your RADIUS server trusts it. +Your Workspace ONE integration's issuing authority signs the certificates that Workspace ONE requests from Smallstep. +It may differ from the authority behind a credential you created in Step 1, so make sure your RADIUS server trusts it. Find your issuing authority in the Smallstep console: @@ -664,29 +664,32 @@ so Smallstep can associate each certificate with the Workspace ONE device that r - **Root Certificates**: **Credentials 2** 7. Choose **Next**, select a **Smart Group** containing your test devices, and choose **Save & Publish** -Set both **Root Certificates** and **Trusted Server Domain**. -Current Android versions refuse to join an enterprise network that doesn't validate the RADIUS server. +Set both **Root Certificates** and **Trusted Server Domain**, +because current Android versions won't join an enterprise network unless they can validate the RADIUS server. #### Verify -When a device receives the profile, Workspace ONE requests a single-use challenge from Smallstep, -and the device enrolls for its certificate and joins the network without prompting. +When a device receives the profile, Workspace ONE requests a single-use challenge from Smallstep. +The device then enrolls for its certificate and joins the network without prompting the user. - In the Smallstep dashboard, [Audit](https://smallstep.com/app/?next=/audit) shows an **X.509 certificate issued** event for each certificate. -- In Workspace ONE, open the device's details. The **Profiles** tab shows the install status, - and **More → Troubleshooting → Event Log** shows each step, from **Profiles Install Initialized** to **Profiles Install Processed**. - On Android, the log also shows **Certificate Issued** for your Smallstep CA resource. +- In Workspace ONE, open the device's details. The **Profiles** tab shows the install status. + **More → Troubleshooting → Event Log** lists each step from **Profiles Install Initialized** to **Profiles Install Processed**, + and on Android it also shows **Certificate Issued** for your Smallstep CA resource. +- On iOS, go to **Settings → General → VPN & Device Management**, open the Workspace ONE profile, and look for the SCEP certificate. + +#### Troubleshoot + - If the profile stays pending, select it on the device's **Profiles** tab and choose **Install** to push it to the device. -- On iOS, go to **Settings → General → VPN & Device Management**, open the Workspace ONE profile, and check for the SCEP certificate. -- If an Android device shows **Hub Registered** or **Android Management: Android (Legacy)**, it isn't managed through Android Enterprise and won't receive the profile. +- If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your issuing authority's root + (see [Trust your issuing authority on your RADIUS server](#trust-your-issuing-authority-on-your-radius-server)). +- An Android device that shows **Hub Registered** or **Android Management: Android (Legacy)** isn't managed through Android Enterprise and won't receive the profile. Check that Android EMM registration is complete, and that **Groups & Settings → All Settings → Devices & Users → General → Enrollment → Management Mode** doesn't enroll Android devices without MDM management. Then re-enroll the device. - To add a work profile to an Android device that's already set up, enroll it as employee-owned. - Corporate-owned Android Enterprise modes are provisioned during setup of a new or factory-reset device. -- If the work profile is paused (**Work apps** turned off on the device), the device won't check in or install profiles. -- If the certificate is installed but the device can't join the network, check that your RADIUS server trusts your issuing authority's root - (see [Trust your issuing authority on your RADIUS server](#trust-your-issuing-authority-on-your-radius-server)). + Corporate-owned Android Enterprise modes are provisioned when a new or factory-reset device is set up. +- While the work profile is paused (**Work apps** turned off on the device), the device doesn't check in or install profiles. ### Windows with Intune (SCEP)