Search Discussions:
Advanced Search...
Welcome to Nokia Support Discussions! Here you can share advice and tips with thousands of other Nokia users around the world in English. Many Nokia employees also follow and participate in the discussions, see our guidelines for more information. Everyone can search and read the discussions, but to post your own question or reply to others, simply login with your Nokia account. If this is your first time here, you can choose an alias to represent you. And if you don't have a Nokia account yet, please register.
Reply

Re: 5800 XM: Issues with WPA (and EAP authorizatio...

Contributor
Posts: 5

5800 XM: Issues with WPA (and EAP authorization)

Hello.

 

I've just bought my new 5800, and I'm over all very satisfied with it, I am how ever experiencing some issues with the WLAN connection at my University. They are using a WPA/WPA2 encryption, and a EAP plug-in. I've spoken with the IT-department, and he told me to use the "EAP-LEAP" plug-in as this is the only plug-in that prompts me for an username, and a password (which is required to logon).

 

My issue:

When I search for the WLAN, it is found, and has a very good signal strength, when I choose connect it pops up, and prompts me for a username, and a password, but when I type in my information, and presses OK, it says "No WLAN network found" (free translation from Danish)

 

I've updated the 5800 software, and tried different EAP plug-ins, but I'm having a hard time figuring out where the problem domain is - is it the EAP plug-in? Is it the Symbian software? Is it the WLAN?

 

If there is any information missing, let me know

 

Best regards

Kasper 

Please use plain text.
Contributor
Posts: 5

Re: 5800 XM: Issues with WPA (and EAP authorization)

Bump? Hope somebody have any idea on what to try?
Please use plain text.
Sage
Posts: 134

Re: 5800 XM: Issues with WPA (and EAP authorization)

It sounds a bit like the WLAN network your trying to connect to might not necessarily support EAP-LEAP authentication method.

 

Was your IT department really confident about which EAP method you should be using on the phone? Just thinking that if they made assumptions about which EAP type you should be using, entirely based on "password prompting" then EAP-LEAP might not be the correct one.

 

There are plenty of other EAP authentication methods in addition to LEAP that provide possibility for prompting the username and password during authentication. Some of the common ones are EAP-TTLS with MSCHAPv2, EAP-PEAP with EAP-MSCHAPv2 and EAP-PEAP with EAP-GTC.

 

If you are not completely sure about the LEAP then you might wan't to double check which EAP type(s) your network requires and supports, making it easier to find instructions and tips regarding your configuration.

 

One thing perhaps worth checking apart from EAP methods and their settings is that if your WLAN network is in mixed WPA/WPA2 mode you should make sure that "WPA2 Only" setting is NOT enabled on your phone's WLAN security settings.

Please use plain text.
New Member
Posts: 3

Re: 5800 XM: Issues with WPA (and EAP authorization)

I'm having the same problem. We use a WPA Enterprise wifi network with EAP-PEAP, MSCHAPv2. I have installed the authority certificate and configured everything else I can see. But it takes a long time trying to connect, then all the SSIDs in the list disappear, and I get a "No WLAN network found." When I quit that dialog, the networks all reappear.

 

This sounds like a bug?

Please use plain text.
New Member
Posts: 3

Re: 5800 XM: Issues with WPA (and EAP authorization)

OK, I got it working. The mistake I made was selecting "Realm in use: From Certificate" (on the EAP-PEAP settings page). I changed it to "user defined" and left "Realm" blank, and now I can connnect.
Please use plain text.
Contributor
Posts: 5

Re: 5800 XM: Issues with WPA (and EAP authorization)

Okay, great work cagilaba!

 

Do you have any idea how to retrieve the certificate? My IT-department cannot help me get the certificate.

 

Thanks in advice.

 

 

//Kasper 

Please use plain text.
Sage
Posts: 134

Re: 5800 XM: Issues with WPA (and EAP authorization)


lhadrepsak wrote:

Okay, great work cagilaba!

 

Do you have any idea how to retrieve the certificate? My IT-department cannot help me get the certificate.

 

Thanks in advice.

 

 

//Kasper 


 

Check following solution for some instructions how to export certificates from Windows PC:

 

/discussions/board/message?message.uid=420880#U420880

 

Naturally for this to work you should first have understanding which are the exact certificate(s) used by the authentication server on your WLAN infrastructure and then you would need have to a Windows PC which contains these particular certificate(s) so you can export them to a file and install on your phone.

 

Depending on which EAP authentication method you are planning to utilize you might need import only the correct "Authority Certificate" to your phone (for EAP-PEAP, EAP-TTLS, EAP-FAST) but in case your WLAN network requires EAP-TLS authentication then you will also need a "Personal Certificate" (client/user) to be installed on the phone in addition to Authority Certificate.

Please use plain text.
New Member
Posts: 3

Re: 5800 XM: Issues with WPA (and EAP authorization)

I'm afraid it is bug. I have the same problem.

I try to connect to WPA/WPA2 Wifi using EAP-TLS. All settings are filled correctly (as it is on the laptop - where it works OK).

When I'm trying to connect, I'm prompted for the password to certificated store, but during writing this password, all WLANs disapper and I have the same message "No WLAN network found". It takes several seconds and then the WLANs list is restored and I can see the WLANs again. There is no problemwith the WLAN signal - laptop works fine...

 

Please use plain text.
Sage
Posts: 134

Re: 5800 XM: Issues with WPA (and EAP authorization)


mxmx wrote:

I'm afraid it is bug. I have the same problem.

I try to connect to WPA/WPA2 Wifi using EAP-TLS. All settings are filled correctly (as it is on the laptop - where it works OK).

When I'm trying to connect, I'm prompted for the password to certificated store, but during writing this password, all WLANs disapper and I have the same message "No WLAN network found". It takes several seconds and then the WLANs list is restored and I can see the WLANs again. There is no problemwith the WLAN signal - laptop works fine...

 


This problem you are experiancing with EAP-TLS (no time to enter certificate store password) might be caused by the fact that WLAN access point has a relatively short EAP response timeout value towards the clients. This timeout might be either configured to short (few seconds) or it might be fixed to some short value in the AP implementation.

 

What might happen in your case is that WLAN access point is not waiting long enough for EAP client (your phone in this case) to respond during the EAP authentication sequence. In case of EAP-TLS phone requires user to enter certificate store password (prompted only once) which naturally causes certain delay to phone's EAP response time.

 

WLAN AP that has very short EAP timeout configuration might consider your EAP-TLS authentication attempt as a failure (prematurely) and due to this "failure" AP deauthenticates the phone completely in the middle of the EAP authentication sequence. Similar problem might occur with any EAP client device against and it also applies to some other EAP authentication methods like e.g. EAP-MSCHAPv2 and EAP-GTC which might require user to enter their username and password credentials during the ongoing EAP authentication sequence.

 

Basically easiest way to try and workaround this problem (unless you have possibility to increase WLAN AP's EAP response timeout parameters) is configuring your phone so that it will not require certificate store password to be entered during the initial EAP-TLS authentication. You can prevent certificate store password prompts by moving your client certificate (the one you have configured to be used by EAP-TLS) from phone's "Personal Certificate" store to "Phone Certificate" store which does not require certificate store password to be entered before certain client certificate can be utilized for authentication.

 

On your 5800XM go to:

 

Settings -> Phone -> Phone Management -> Security -> Certificate Management -> Personal Certificates

 

Highlight the particular personal (client) certificate you have previously installed on the phone to be used for EAP-TLS and select  Options -> Move to Phone Certificates

 

Select Yes when warned about the potential security risks of Phone Certificates not requiring certificate store password to be entered. Enter the certificate store password when prompted and your client certificate will be moved to "Phone Certificates" certicate storage. After this phone will not prompt you to enter certificate store password when utilizing the given client certificate during EAP-TLS authentication.

 

Exit from the Certificate Management application and double check that your WLAN internet access point's EAP-TLS settings are still having your client certificate (the one you just moved) selected as a Personal Certificate for EAP-TLS authentication.

Please use plain text.
Registered Member
Posts: 4

Re: 5800 XM: Issues with WPA (and EAP authorization)

Help! I have just has the 5800 and am pleased so far! Am trying to connect wirelessly to my SKY Sagem router. Same probs as described here; it connects but then says it cannot find a setting, etc. Can you please give me an idea as to how I may overcome this? Am not at all familiar with 'certificates' etc, so please make it simple and idiot proof!!

 

Many thanks,

 

Simon

Please use plain text.
New Member
Posts: 3

Re: 5800 XM: Issues with WPA (and EAP authorization)

saataja wrote:

This problem you are experiancing with EAP-TLS (no time to enter certificate store password) might be caused by the fact that WLAN access point has a relatively short EAP response timeout value towards the clients. This timeout might be either configured to short (few seconds) or it might be fixed to some short value in the AP implementation.

...

 


Hi saataja, you are right !!

 

When I moved the certificate to the phone certificate store then the connection works fine.

Thank you very much for your advice !!

 

Only the security risk about using my personal certificate without password prompt could be the reason to leave using this WLAN. But this is not problem of the phone (my apology to Nokia) but of the WLAN access point setting ... 

 

Please use plain text.
Registered Member
Posts: 4

Re: 5800 XM: Issues with WPA (and EAP authorization)

Thanks. Could you tell me how to move the certificate please?

 

Thanks

 

Simon

Please use plain text.
New Member
Posts: 3

Re: 5800 XM: Issues with WPA (and EAP authorization)

see the description by saataja above (the 9th message).

 

There are paragraphs starting with:

Settings -> Phone -> Phone Management -> Security -> Certificate Management -> Personal Certificates .....

Please use plain text.
Registered Member
Posts: 4

Re: 5800 XM: Issues with WPA (and EAP authorization)

Thanks. I have tried this but there are no personal certificates available. Can I rectify this?

 

Thanks again, Simon

Please use plain text.
Sage
Posts: 134

Re: 5800 XM: Issues with WPA (and EAP authorization)


simon1971 wrote:

Thanks. I have tried this but there are no personal certificates available. Can I rectify this?

 

Thanks again, Simon


Note that certificates discussed earlier in this thread are relevant only for more advanced WPA/WPA2-Enterprise (EAP) WLAN authentication methods such as EAP-PEAP or EAP-TLS. Typically you don't have to worry about EAP settings and certificates when trying to connect your phone to your home WLAN network since these type of EAP authenticated WPA/WPA2 security schemes are more likely to be utilized in corporate or campus WLAN networks (universities etc.)

 

It sounds that you are trying to simply connect to your home WLAN access point (or WLAN enabled router) in which case your AP is more likely to require WPA/WPA2-PSK (Preshared Key) authentication or simple WEP encryption.

 

Both WEP and WPA/WPA2-PSK security modes won't require you to have any certificates installed on your phone but instead you simply enter the correct "password" (WEP key or WPA/WPA2-Preshared Key) in to your phone that matches exactly what has been configured on your WLAN access point.

Have you taken a look at your WLAN access point's configuration interface (usually by accessing AP's  browser based configuration interface or via separate management application from your computer)? Access point's user manual should help you getting started and first thing to do is figure out what WLAN security mode is currently enabled on your access point and what is the correct encryption key / password you are expected to enter to your phone.

Sometimes access point's default WEP encryption key and/or WPA/WPA2 Preshared Key might also be mentioned e.g. on a sticker on the WLAN access point.

 Some WLAN access points might also be shipped without any WLAN security being enabled by default in which case you should basically be able to connect your phone to your WLAN network without any security configuration on the phone side, naturally also in this case you need to know what is the SSID (=network name) of your WLAN network in case phone is able find more than one WLAN network while scanning available networks.

Note that in case your WLAN network is completely open (unencrypted and unauthenticated) then basically anyone including your neigbours etc. can use your WLAN connection thus it's a good idea to enable e.g. WPA/WPA2-PSK security mode on the network and configure matching settings on the phone, preventing unwanted people from using your WLAN network or seeing any confidential data you are transmitting over the WLAN connection.

Please use plain text.
Registered Member
Posts: 4

Re: 5800 XM: Issues with WPA (and EAP authorization)

Thanks very much for that. I have been following the steps. I enter the preshare key for the network and it is recognised. The problem then is the phone beeps and says no WLAN. I cannot see what I am doing wrong. Could there be a bug or am I just missing something very obvious and stupid?

 

Thanks once again.

 

Simon

Please use plain text.
Sage
Posts: 134

Re: 5800 XM: Issues with WPA (and EAP authorization)


simon1971 wrote:

Thanks very much for that. I have been following the steps. I enter the preshare key for the network and it is recognised. The problem then is the phone beeps and says no WLAN. I cannot see what I am doing wrong. Could there be a bug or am I just missing something very obvious and stupid?

 

Thanks once again.

 

Simon


 

Not sure about the SKY Sagem router you are having but some of the operator branded WLAN routers might have some special button(s) on the router that need to be pressed before they allow new WLAN clients (=your phone) to associate for the first time.

 

There might also be some settingSs) on the router's web configuration pages related to whether router automatically accepts new previously unknown WLAN clients to associate. This is kind of like MAC address filtering, where router allows only "known" clients to connect and rest are simply not getting access until user either allows particular client (MAC address) or presses a button and immediately after that connects the client to router's WLAN network, after which this particular client becomes "known" to the router and client can connect in the future without any additional steps.

 

Have you had a look at your router's user manual, getting started documentation or similar? Also check if your router's configuration interface has any settings resembling to MAC address filtering or "Allow new clients to associate automatically" etc.

 

If you need to enter your phone's WLAN MAC address manually in to the WLAN router configuration you check it from your phone either by looking at the sticker behind the battery or by entering a code: *#62209526# on your phone while it is showing the idle screen (home screen).

Please use plain text.
New Member
Posts: 1

Re: 5800 XM: Issues with WPA (and EAP authorization)

Where did you find that Plug-in ??

 

and btw are you danish :smileyhappy:

Please use plain text.
Registered Member
Posts: 1

Re: 5800 XM: Issues with WPA (and EAP authorization)

i mistakenly entered the wrong WPA code, and now the phone will not let me re-enter a diff code.It says the WLAN network is "known" but then denies access because of wrong access code.
Please use plain text.
Sage
Posts: 134

Re: 5800 XM: Issues with WPA (and EAP authorization)


uncledeejay wrote:
i mistakenly entered the wrong WPA code, and now the phone will not let me re-enter a diff code.It says the WLAN network is "known" but then denies access because of wrong access code.

 

You probably need to manually edit  the Internet Access Point (or delete and recreate a new one) that contains the wrong WPA-PSK code.

 

Go to Settings -> Connectivity -> Destinations -> Internet

 

Within "Internet" Destination, look for an Access Point name that matches your WLAN network name (SSID) and select Options -> Edit for the this Access Point. Double check that "WLAN network name" is correctly entered and "WLAN Security Mode" is set to "WPA/WPA2". Go to "WLAN Security Settings" and make sure that "WPA/WPA2" is set to "Pre-shared key".  Enter the new WPA-PSK matching your WLAN access point's code in to the "Pre-shared key" field (note that PSK is case sensitive). Ensure that "WPA2 Only mode" is set to Off and go "Back" few times to exit the configuration menus and save your changes.

 

Another option is that you delete (Options -> Delete) your WLAN Internet Access Point that contains the wrong WPA-PSK code and re-create new Access Point similarly than what you had done previously while wrong WPA-PSK code was entered by mistake. E.g. by going to Settings -> Connectivity -> Wireless LAN -> and using the "WLAN Wizard". Note that WLAN Wizard should now show your WLAN network as "Unknown" assuming that you successfully deleted existing incorrectly configured Internet Access Point as instructed above.

Please use plain text.