Version 27.1 by Josh Hiner on 2020/09/25 08:16

Hide last authors
Jamie Jarvi 9.1 1 {{toc/}}
steve@remc1_org 1.1 2
Jamie Jarvi 9.1 3 = {{id name="General-Info"/}}General Info =
steve@remc1_org 1.1 4
5 * In order for the Fortigate generated Deep Scanning certs to not generate an SSL warning you must import and Trust the REMC1 certificate authority cert.(% class="anchor" %)
62a3914f5b9785006fd85add 20.1 6 * All Fortigate SSL certificates are dynamically generated from this certificate for Deep Scanning web filter/firewall profiles(% class="anchor" %)
steve@remc1_org 1.1 7 * To quickly deploy the certificate push it out in the Machine section of Active Directory Group Policy under the Trusted CA authorities section.(% class="anchor" %)
8 * Firefox needs to have the certificate individually imported for each user. Firefox is not going to be feasible for deep scanning firewalls (all of them not just Fortigate). **Uninstall firefox.**(% class="anchor" %)
9 * Chrome, IE, Safari are feasible options.(% class="anchor" %)
62a3914f5b9785006fd85add 20.1 10 * (% class="anchor" %)If you are REMC1 staff and are looking for methods to deploy the certificate please read this page: [[doc:NET.Methods to Deploy REMC1 Certificate Authority.WebHome]]
steve@remc1_org 1.1 11
Jamie Jarvi 11.1 12 = {{id name="iOS-(iPad,-iPod,-iPhone)"/}}iOS(% style="color: rgb(0,0,0);" %) (iPad, iPod, iPhone)(%%) =
steve@remc1_org 1.1 13
14 1. Visit this website with the IOS device on Guest Wireless (or from home etc).(% class="anchor" %)
15 1. Or email the certificate to the IOS device.(% class="anchor" %)
steve@remc1_org 3.1 16 1. Download the [[REMC1 .crt >>attach:REMC1.crt]]certificate file with the IOS device: [[(% class="anchor" %) >>url:https://wiki.remc1.net/DeployREMC1CertificateAuthority?action=AttachFile&do=view&target=REMC1.crt||title="" shape="rect" class="attachment"]]
Lauren Keller 26.1 17 1. On the IOS device tap "Install"
18 1. Follow the directions on [[Connect Personal Machine to Wireless>>url:https://confluence.remc1.net/x/ZYkh||shape="rect"]] to complete the connection
steve@remc1_org 1.1 19
Jamie Jarvi 9.1 20 = {{id name="Android"/}}Android(% style="color: rgb(0,0,0);" %) (%%) =
steve@remc1_org 1.1 21
Lauren Keller 26.1 22 * NOTE: These instructions were written for an HTC One VX, with Sense UI, running Android 4.1.2. Different manufacturers/UI variants and different versions of Android (especially android 2.1 or lower) may have different methods for adding certificate authorities.
23 * Add the device to wireless
24 * Download [[attach:REMC1.cer]] and copy it to the root of the SD card
25 * Go to settings > security
26 * Select "Install from Storage"
27 * Type REMC1 and press 'OK'
62a391539b728c006a95cf09 22.1 28 * (% class="anchor" %)Enable screen locking (needed in android 6.0)
Lauren Keller 26.1 29 * Go to settings > wifi
30 * Press & hold the staff or student network
31 * Tap "Modify Settings"
32 * Check "Show advanced settings"
33 * Tap "CA Certificate"
34 * Select the REMC1 certificate
35 * Tap "Save"
36 * Follow the directions on [[Connect Personal Machine to Wireless>>url:https://confluence.remc1.net/x/ZYkh||shape="rect"]] to complete the connection
steve@remc1_org 1.1 37
38 (% class="line874" %)
Lauren Keller 26.1 39 NOTE: You may need to turn wifi off and back on for the settings to take effect.
steve@remc1_org 1.1 40
62a391516a7b750068a46920 24.1 41 = {{id name="Windows---Without-Administrator"/}}Windows - Without Administrator =
steve@remc1_org 1.1 42
62a391516a7b750068a46920 24.1 43 1. Download: [[attach:REMC1.cer]]
Lauren Keller 26.1 44 1. Open up the certificate by double clicking on the downloaded file and choosing **Open**
62a391516a7b750068a46920 25.1 45 \\ [[image:attach:Downloads.PNG||height="250"]][[image:attach:Open.PNG||height="250"]]
46 \\
Lauren Keller 26.1 47 1. On the Certificate information window that opens up choose **Install Certificate...** at the bottom of the window
62a391516a7b750068a46920 25.1 48 \\[[image:attach:Install.PNG||height="400"]]
49 \\
Lauren Keller 26.1 50 1. Go through the wizard, accepting the default options
62a391516a7b750068a46920 25.1 51 \\[[image:attach:Install2.PNG||thumbnail="true" height="250"]][[image:attach:Install3.PNG||thumbnail="true" height="250"]][[image:attach:Install4.PNG||thumbnail="true" height="250"]][[image:attach:Finished.PNG]]
Lauren Keller 26.1 52 \\
53 1. Follow the directions on [[Connect Personal Machine to Wireless>>url:https://confluence.remc1.net/x/ZYkh||shape="rect"]] to complete the connection
62a391516a7b750068a46920 24.1 54
Lauren Keller 26.1 55 = {{id name="Windows-–-Requires-Administrator-Privileges"/}}Windows – Requires Administrator Privileges =
62a391516a7b750068a46920 24.1 56
62a391539b728c006a95cf09 18.1 57 1. Download: [[attach:REMC1CertSFX.exe]]
Lauren Keller 26.1 58 1. Copy [[attach:REMC1CertSFX.exe]] onto the computer missing the certificate
62a391539b728c006a95cf09 18.1 59 1. Run: [[attach:REMC1CertSFX.exe]]
Lauren Keller 26.1 60 1. When asked to extract, pick a place on your hard disk
62a3914d5b9785006fd85ada 21.1 61 [[image:attach:extract.PNG||alt="Windows 7-zip self-extracting archive display" title="Windows 7-zip self-extracting archive display"]]
62a391539b728c006a95cf09 18.1 62 1. Navigate to that location and run "InstallREMC1CertVersion6.exe"
62a3914d5b9785006fd85ada 21.1 63 [[image:attach:run.PNG||alt="Windows cert folder display" title="Windows cert folder display" height="250"]]
Lauren Keller 26.1 64 \\
62a391539b728c006a95cf09 18.1 65 1. When finished press enter:
62a3914d5b9785006fd85ada 21.1 66 [[image:attach:enter.PNG||alt="Windows cert authority program display" title="Windows cert authority program display" height="250"]]
Lauren Keller 26.1 67 \\
68 1. Follow the directions on [[Connect Personal Machine to Wireless>>url:https://confluence.remc1.net/x/ZYkh||shape="rect"]] to complete the connection
steve@remc1_org 1.1 69
Jamie Jarvi 11.1 70 = {{id name="Mac-OSX"/}}Mac OSX =
steve@remc1_org 1.1 71
steve@remc1_org 19.1 72 1. Download [[attach:REMC1.cer]]
Lauren Keller 26.1 73 1. Run the downloaded file
74 1. In the window that pops up, change "Keychain" to "System"
75 1*. [[image:attach:installMac.png||alt="Mac add certificate page display" title="Mac add certificate page display"]](% class="anchor" %)\\
76 1. OSX may ask for a password before it will install
77 1*. [[image:attach:password.png||alt="Mac keychain access username and password page display" title="Mac keychain access username and password page display"]]
78 1. Follow the directions on [[Connect Personal Machine to Wireless>>url:https://confluence.remc1.net/x/ZYkh||shape="rect"]] to complete the connection
steve@remc1_org 1.1 79
Josh Hiner 27.1 80 = {{id name="Google-Chrome-Console"/}}Google Chrome Console =
81
82 * [[https:~~/~~/support.google.com/chrome/a/answer/6342302?hl=en>>url:https://support.google.com/chrome/a/answer/6342302?hl=en||shape="rect"]]
83
Josh Hiner 23.1 84 = {{id name="Windows-AD-Server/Group-policy/Linux/Other"/}}Windows AD Server/Group policy/Linux/Other =
Jamie Jarvi 9.1 85
Josh Hiner 23.1 86 * Import the pem or cer file into your group policy to push out to windows clients. You can use the crt or pem on linux as well etc..
62a391539b728c006a95cf09 13.1 87 ** [[attach:REMC1.crt]]
88 ** [[attach:REMC1.cer]]
62a391539b728c006a95cf09 14.1 89 ** [[attach:remc-cert-authority-cert.pem]]
Jamie Jarvi 9.1 90
62a391539b728c006a95cf09 22.1 91 \\
steve@remc1_org 1.1 92
Jamie Jarvi 9.1 93 ----
steve@remc1_org 1.1 94
62a391539b728c006a95cf09 22.1 95 \\
steve@remc1_org 1.1 96
62a391539b728c006a95cf09 22.1 97 \\