Ultimate S-Tier Wifi Security with EAP-TLS Certificates (feat. Smallstep)

  Рет қаралды 11,269

apalrd's adventures

apalrd's adventures

Күн бұрын

Пікірлер: 45
@nickjongens2169
@nickjongens2169 8 ай бұрын
Thanks, just saw an ad for smallstep and found this video around the same time. You're an S-Tier presenter :)
@apalrdsadventures
@apalrdsadventures 8 ай бұрын
Thanks!
@josealfredfernandes
@josealfredfernandes 3 ай бұрын
@@apalrdsadventures 1 question, can i use network security appliance certificate? eg: sophos? since i alredy have the appliance, ill use that certificate instead, it has many years before it expires
@grantwilcox330
@grantwilcox330 10 ай бұрын
thank you for sharing. slowly learning about using security certificates.
@adrianstephens56
@adrianstephens56 10 ай бұрын
Link-level security has its value (such as for identity protection), but you are trusting the AP - this might make sense at home, but not in public. Therefore, end-to-end security is always necessary. I argued this in the 802.11 standards group many years ago in the context of mesh networks, where you might have great link-level encryption, but have to trust an unknown set of intermediate nodes.
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
You're not trusting the AP though, you're trusting the RADIUS server. The AP is just facilitating the EAP exchange by passing frames along.
@logicalAllyKat
@logicalAllyKat Ай бұрын
Hello, Is there any chance this conflicts with the Windows device guard?
@mjmeans7983
@mjmeans7983 10 ай бұрын
In which use cases would Smallstep not be useful when implementing EAP-TLS? I presume one answer would be when only securing local connections in a network segment that doesn't have internet access at all. Is that correct? Are there other uses cases where Smallstep is not necessary or perhaps even a disadvantage?
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
Depends on if you mean Smallstep SaaS or step-ca (the open-source backend). You can use the open-source backend along with FreeRADIUS to implement everything in this video, except generating mobileconfig files. They are just xml though, and step-ca can do the SCEP bit. So Smallstep (SaaS) is adding a GUI in this case, and also doing the job of configuring FreeRADIUS. Step-CA (open-source backend) is adding a ton of plumbing above what OpenSSL would provide as a CA, especially in supporting enrollment protocols like SCEP, ACME, Nebula, and integrating other types of certs like TLS and SSH into the same system.
@williamlew3127
@williamlew3127 21 күн бұрын
@@apalrdsadventures first, thanks for the very informative video.I was looking into passwordless auth for wifi and found this. i'm getting mixed search results to configure freeradius to do the same as what smallstep does. since most of you videos are about self hosting, would you be consider doing a video to self-host a freeradius server that would replace smallstep?
@apalrdsadventures
@apalrdsadventures 21 күн бұрын
Thanks! I can take a look at FreeRADIUS config. I have another video on FreeRADIUS as well (the private pre-shared-keys video), but it's not using TLS specifically either.
@james-cucumber
@james-cucumber 10 ай бұрын
Super interesting video! (Commenting mostly for the algorithm’)
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
Thanks for that!
@grigory559
@grigory559 6 ай бұрын
Excellent video, thank you so much! Have you found any way to automatically distribute generated certificates on iOS devices? I'm pretty sure my wife won't be happy if I ask her to do that every 3 months 😕
@Dogo.R
@Dogo.R 10 ай бұрын
Why doesnt mac address whitelisting acheive the same thing certificates do?
@gmdc5850
@gmdc5850 10 ай бұрын
I think it is relatively easy to generate MAC addresses, so you could bypass that security feature
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
Yes, devices can easily choose whatever MAC they wish, and MACs are always unencrypted over the air, so it's not hard to find a valid MAC to clone.
@dannylberry
@dannylberry 10 ай бұрын
I've just set this up using my own RootCA for the smallstep PKI. anyone happen to know if you stay under the 20 device cap is it still free? I can see my authorities type is Advanced?
@jagdtigger
@jagdtigger 10 ай бұрын
Id rather not depend on external provider, can i use self signed for this?
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
RADIUS-side you can use a single self-signed cert if you want, or it can be issued by an authority clients trust. Client-side you need an authority to issue certs and then the RADIUS server trusts the authority to validate individual certs. OpenSSL can do this (but it's clunky), and step-ca (the open source backend of Smallstep) can also do this self-hosted. FreeRADIUS would then be configured with the eap module and point at the root certificate used by the clients. The authority doesn't need to be public, but you really do need an authority somewhere.
@jagdtigger
@jagdtigger 10 ай бұрын
@@apalrdsadventures Great 👍, thanks. Id rather spend a few hours figuring this out and writing rudimentary bash scripts to automate it with cron than to scramble when the external provider goes under......
@mjmeans7983
@mjmeans7983 10 ай бұрын
Camera security? Are you aware of any open-source camera firmware that supports EAP-TLS Certificate security so that security cameras can't be eaves-dropped on?
@hasanmujeeb8922
@hasanmujeeb8922 10 ай бұрын
Wow that’s awesome
@hasanmujeeb8922
@hasanmujeeb8922 10 ай бұрын
What’s the firmware?
@mjmeans7983
@mjmeans7983 10 ай бұрын
Okay, so I plan on investigating the github projects ESP32-EAP-TLS-WPA2 and ESP32-CAMERA at some point. Hopefully they will work together well enough to make a much more secure security camera.
@dozerd42
@dozerd42 10 ай бұрын
Does your AP support WPA3 Enterprise for Wifi6 clients, but still support WPA2 for WiFi clients? Not all my devices support Wifi6 yet.
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
Security / 802.11 settings are separate. You can run in WPA2/3 transition and allow clients of either generation, and separately allow 802.11N/AC/AX (on 5Ghz). In WPA-Enterprise, using WPA2/3 transition doesn't have nearly as many downsides as it does in WPA-PSK.
@antonfelin
@antonfelin 10 ай бұрын
На майке "лайка" Написано?
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
Лайка was the name of the first Soviet space dog, hence the dog on the shirt
@dzmitryulasau878
@dzmitryulasau878 10 ай бұрын
I got confused as well 😀
@zyghom
@zyghom 10 ай бұрын
@@apalrdsadventures and now you say you speak Russian ;-)
@andrieshrr
@andrieshrr 10 ай бұрын
I also noticed this t-shirt :D
@ericjohnson2193
@ericjohnson2193 10 ай бұрын
🤔 in theory, could a mobile app be made to do certificate renewal for you?
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
This is how MDMs (Mobile Device Management systems) operate, basically.
@crmeae
@crmeae 10 ай бұрын
Muy interesante video (Truly very interesting video)
@zyghom
@zyghom 10 ай бұрын
earthquake here at 17:55 ? ;-) And btw how many t-shirts in one video? ;-) And hair styles? ;-)
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
More T-shirts / hair styles = the video took a long time to make
@ЕгорСмоленский-х8х
@ЕгорСмоленский-х8х 10 ай бұрын
Здравствуйте! Хотел бы сказать что футболка классная. Спасибо
@ЕгорСмоленский-х8х
@ЕгорСмоленский-х8х 10 ай бұрын
Спасибо за интересные видео. Очень позновательно. Помогли мне продвинуть домашнюю инфраструктуру
@apalrdsadventures
@apalrdsadventures 10 ай бұрын
Glad it's helping you! I don't actually speak Russian, it's a T-shirt of the first dog in space, Лайка
@robertopontone
@robertopontone 10 ай бұрын
Quite unique content, but this time too complex for me 😢
@RomanTruman
@RomanTruman 5 ай бұрын
Like for Лайка :D
How Secure is YOUR WiFi Network?
35:44
apalrd's adventures
Рет қаралды 20 М.
CNIT 140: Windows Internals
39:05
Sam Bowne
Рет қаралды 4,6 М.
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 26 МЛН
Long Nails 💅🏻 #shorts
00:50
Mr DegrEE
Рет қаралды 18 МЛН
proxmox k3s p5.2 - cloudflare WAF rules
12:28
Michael Lundquist
Рет қаралды 73
Self-Hosted TRUST with your own Certificate Authority!
26:25
apalrd's adventures
Рет қаралды 36 М.
Should you be using WiFi 7 or WPA3? Best Wi-Fi setup?
27:20
David Bombal
Рет қаралды 76 М.
Smallstep Enterprise Relay
5:11
Smallstep
Рет қаралды 72
Secure Your Self-Hosted Network with Wazuh
21:49
Techdox
Рет қаралды 109 М.
Measuring EVERY CIRCUIT in my house ... for science
15:29
apalrd's adventures
Рет қаралды 3,6 М.
Securely Expose your Homelab Services with Mutual TLS
20:35
apalrd's adventures
Рет қаралды 10 М.
Turning Proxmox Into a Pretty Good NAS
18:31
apalrd's adventures
Рет қаралды 259 М.
Quick and Easy Local SSL Certificates for Your Homelab!
12:08
Wolfgang's Channel
Рет қаралды 856 М.
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 26 МЛН