Guest Portal - The Network you are trying to join has security issues.

ShaunCro
Here to help

Guest Portal - The Network you are trying to join has security issues.

So today I was testing a QR code to all for easier connections to our Guest Wifi, which see's around 3000 users a week. When I connected I got an error that the Network had security issues.

 

ShaunCro_0-1761246880702.png


So I immediately check on my laptop, no issue, find someone with an apple device, and that is fine too. Go back and check the cert and it looks fine, it hasn't expired, can't see anything of wrong, but android devices are saying that the cert is untrusted.

ShaunCro_1-1761247039795.jpeg

 

Do a little digging around and find a post on Cloudfares community, seems that Android has decided to remove ssl.com as a trusted CA from the android system. This particular cert is issued by ssl.com, so seems like who ever is as lucky as we are, are going to be suffering till either the cert is renewed with a different CA, or Androids next update includes the ssl.com CA cert again. Because there is no way for us to fix it, and support think that Android possibly fixing it in the next release, which should be around this time next year, is the solution to the ticket I logged earlier. Should be fun. 

 

CA cert for the guest wifi.

ShaunCro_2-1761247482601.png


Apparently both Cloudfare and They are aware of it, but can't do anything.

 

So instead of thinking out of the box on this one and issue a letsencrypt cert for the interim, or asking cloudfare to rekey the cert with another provider, anything. Thats the solution. Wait and see.

 

I can't change the wifi connection process till Jan, we in the middle of exams and students use the network to write. And the predominant device that connects to our Guest Wi-Fi is an Android phone. So if you start getting complaints. This is why.

 

https://community.cloudflare.com/t/android-webview-ssl-error-certificate-authority-is-not-trusted-wh...

 

 

7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

What an annoying situation, good luck.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

What a pain!

 

I'm a LetsEncrypt fan ...

ShaunCro
Here to help

Me too, setup certbot, and forget about it. It just works. Love letsencrypt.

PhilipDAth
Kind of a big deal
Kind of a big deal

Make sure you open a support ticket about this.

ShaunCro
Here to help

I did. Ticket is pending closure waiting for android or cloudfare to fix it.

Khaan
New here

HI Sir, i am also facing same issue iOS fine but android have this issue. can you please help me to resolve it.

what's the main root cause for android devices and what i need to change to resole the issue.

ShaunCro
Here to help

The Certificate Authority is no longer trusted by Android, the root cert that confirms the authenticity of the provider of the certificate used to encrypt the Wi-Fi connections has been removed by Android, this means that the device doesn't see the certificate as valid because it has no way of confirming that the authenticity of the certificate chain. Unfortunately we have 3 choices,

 

1. Host our own based on radius with our own trusted certs

2. Go with a 3rd party solution.

3. Wait for someone at cisco to realize they can use a cert from another provider to encrypt *.network-auth.com.

Get notified when there are additional replies to this discussion.