Many organizations nowadays do not prefer password-based W-Fi Authentication solutions due to security threats. So, due to technological
advancement, they have started to choose 802.1x certificate-based W-Fi Authentication (EAP-TLS), which offers more security than credential-based (Password) authentication and a better user experience.
EAP-TLS requires a public key infrastructure (PKI) to enroll and authenticate the certificates for PingId W-Fi authentication. PingId is an Identity Provider like Azure, Octa, and Google. SecureW2 PKI can configure WPA2-enterprise with Ping Identity by using SAML-Application to enroll the certificates for Wi-Fi authentication.
Setting up PingIdentity Wi-Fi Authentication
The Ping Identity Wi-Fi Authentication can be set up with the help of SAML Authentication, where the end-user can enter the credentials. The credentials will be sent to and verified by PingId. After verification, The PingId sends the attributes to the SAML App and shares them with SecureW2 PKI To issue PingIdentity 802.1x certificates.
Configuring an Identity Provider for PingID
An Identity Provider is the type of system that verifies the User/Device profiles.The following steps to create an IDP for Ping Identity:
- Log in to the SecureW2 Management Portal.
- Go toΒ Identity Management > Identity Providers.
- On theΒ Identity Providers page, clickΒ Add Identity Provider.
- In the Basic section:
- Enter theΒ NameΒ andΒ DescriptionΒ of the IDP in the corresponding fields.
- From theΒ TypeΒ drop-down list, selectΒ SAML.
- From theΒ SAML VendorΒ drop-down list, selectΒ Ping Identity.
- ClickΒ Save.
- On the displayed page, click theΒ ConfigurationΒ tab.
- In theΒ Service Provider (SP) info, copy theΒ ACS URLΒ andΒ Entity IDΒ values and save them on a word or text file.
Configuring a SAML App in the PingIdentity Portal
The SAML App will allow users to enter their credentials in Pingid, which later passes to the user IDP for verification.
Steps to create a SAML App for the PingIdentity Portal.
- Log in to the PingIdentity portal with your credentials.
- On the left pane, click on
icon.
- On the displayed page, clickΒ Add a SAML appΒ and then click theΒ ConnectionsΒ icon on the left pane.
- On theΒ ApplicationsΒ page, click the
icon. TheΒ Add ApplicationΒ dialog box appears.
- Enter theΒ NameΒ andΒ DescriptionΒ for the application in the corresponding fields.
- In the ChooseΒ Application TypeΒ section, selectΒ SAML Application.
- ClickΒ Configure.
- In theΒ SAML ConfigurationΒ dialog box:
- Select theΒ Manually EnterΒ option.
- In theΒ ACS URLsΒ field, enter theΒ ACS URLΒ value obtained from the SecureW2 Management Portal.
- In theΒ Entity IDΒ field, enter theΒ Entity IDΒ value obtained from the SecureW2 Portal.
- ClickΒ Save.
- From the left pane, selectΒ Identities. The Users page is displayed.
- Click theΒ +Add UserΒ button on the right side.
- In theΒ Add UserΒ window, under PERSONAL section enter a suitable name in the GIVEN NAME field.
- In theΒ COMPANY INFORMATIONΒ section:
- From theΒ PopulationΒ drop-down list, selectΒ Technical AdministratorsΒ .
- In theΒ USERNAMEΒ field, enter the username.
- ClickΒ Save.
- In the left pane, clickΒ Connections.
- On theΒ ApplicationsΒ page, select the SAML app you created earlier (see the Configuring a SAML App section).
- Click theΒ ConfigurationΒ tab and then click theΒ Download MetadataΒ button.
Uploading Metadata to SecureW2
- Log in to the SecureW2 Management Portal.
- Go toΒ Identity Management > Identity Providers.
- On theΒ Identity ProvidersΒ page, select the IDP created for PingID (see the Configuring an Identity Provider for PingID section) and click the Edit link.
- Click theΒ ConfigurationΒ tab and in theΒ Identity Provider (IDP) InfoΒ section:
- For theΒ MetadataΒ field, clickΒ Choose FileΒ and select the Metadata file downloaded from the PingID portal.
- ClickΒ Upload.
- ClickΒ Update
Configuring Attribute Mapping In the PingId
Steps to configure the Attribute Mapping PingId portal.
- In the PingIdentity portal, click the SAML app created earlier.
- TheΒ OverviewΒ window is displayed. Go toΒ Attribute Mapping, click the Attributes button to edit the attribute mappings.
- In theΒ Edit Attribute MappingsΒ window, click theΒ + AddΒ button to add the required application attributes under the Attributes column and select relevantΒ PingOne MappingsΒ from the drop-down list.
- ForΒ Email Attributes, under the Applications column, enterΒ emailΒ and selectΒ Email AddressΒ from the drop-down list.
- ForΒ User Principal Name (UPN), enterΒ upnΒ and selectΒ Email AddressΒ from the drop-down list.
- ForΒ displayName, enter a display name and selectΒ UsernameΒ from the drop-down list.
- ClickΒ Save.
Configuring the Attributes in the SecureW2 Management Portal
- In the SecureW2 Management Portal, go toΒ Identity Management > Identity ProvidersΒ and click theΒ EditΒ link of the PingID IDP you created.
- On the displayed screen, click theΒ Attribute MappingΒ tab.
- On the displayed screen, click theΒ AddΒ button.
- In theΒ Local AttributeΒ field, typeΒ emailΒ to identify the attribute locally. From theΒ Remote AttributeΒ drop-down list, selectΒ User Defined. In the adjacent text box, type email, and then clickΒ Next.
- In theΒ Local AttributeΒ field, typeΒ upnΒ to identify the attribute locally. From theΒ Remote AttributeΒ drop-down list, selectΒ User Defined. In the adjacent text box, typeΒ upn, and then clickΒ Next.
- In theΒ Local AttributeΒ field, typeΒ displayNameΒ to identify the attribute locally. From theΒ Remote AttributeΒ drop-down list, selectΒ User Defined. In the adjacent text box, typeΒ DisplayName, and then clickΒ Next.
Creating a Group in the Ping Identity Portal
- In the PingIdentity portal, in the left pane, clickΒ Identities > GroupsΒ and then click the icon on theΒ GroupsΒ page to add a new group.
- In theΒ Group NameΒ field, enter the name of the group.
- From theΒ PopulationΒ drop-down list, selectΒ Technical Administrators.
- ClickΒ Save. The group is successfully created.
- On the displayed window, click theΒ UsersΒ tab and then click theΒ + Add Users IndividuallyΒ button.
- The list of users is displayed. Select the users by clicking theΒ +Β icon.
- ClickΒ Save.
Configuring Policies in SecureW2
Now that weβve set up the connection between SecureW2 and PingIdentity, we need to configure a few policies so we can enroll our users for certificates.
Creating an Authentication Policy
- In the Management Portal, go toΒ Policy Management > AuthenticationΒ and clickΒ Add Authentication Policy.
- In the Basic section, enter theΒ NameΒ andΒ Display DescriptionΒ of the policy in the corresponding fields.
- ClickΒ Save.
- Click theΒ ConditionsΒ tab. From theΒ ProfileΒ drop-down list select the profile.
- ClickΒ Update.
- Click theΒ SettingsΒ tab. From theΒ Identity ProviderΒ drop-down list, select the Ping IDP created earlier.
- ClickΒ Update.
Creating a Role Policy
- Navigate toΒ Policy Management > RolesΒ and clickΒ Add Role.
- On the displayed page, In theΒ BasicΒ section, enter theΒ NameΒ andΒ DescriptionΒ of the Role policy in the corresponding fields.
- ClickΒ Save.
- On the displayed page click theΒ ConditionsΒ tab.
- From theΒ Identity ProviderΒ drop-down list, select the Ping IDP created earlier.
- ClickΒ Update.
Creating an Enrollment Policy
- Go toΒ Policy Management > EnrollmentΒ and clickΒ Add Enrollment Policy.
- On the displayed page, enter theΒ NameΒ andΒ DescriptionΒ of the policy in the corresponding fields.
- ClickΒ Save.
- On the displayed page, click theΒ ConditionsΒ tab.
- From the Role list, select the role created earlier.
- From theΒ Device RoleΒ list, selectΒ DEFAULT DEVICE ROLE POLICY.
- ClickΒ Update.
After creating the Role and Enrollment policies, we have to republish the Secure SSID profile in the Network Profiles page.
Testing Certificate Enrollment
- Go toΒ Device Onboarding > Network Profiles.
- In the Network Profiles table, select the profile we created earlier and clickΒ Republish.
Note:Β After you modify a profile, republish the profile anytime for the changes to be effective. - In theΒ Republish Network Profile window, in theΒ NameΒ field, enter a name for the profile and click OK.
- After republishing the profile, clickΒ View. TheΒ Landing PageΒ is displayed.
- Click theΒ JoinNowΒ button. A dissolvable client will run depending on the operating system of the device.
- Once the client runs, users will be redirected to the PingIdentity SAML app and prompted for their credentials.
- Once the credentials are verified, the SecureW2 client will proceed to enroll the device for a certificate.
SecureW2 can quickly integrate with PingId and easily get secure Wi-fi access. And our Turnkey Managed PKI, 802.1x onboarding, and Cloud RADIUS server offer a better user experience and outstanding network facility.
SecureW2 can serve as the most cost-effective solution to the organizationβs needs. Click here to see our pricing details.
























