• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How deploy Certificate automation to mobile (IOS, Android) use Squid Proxy?

Scheduled Pinned Locked Moved Firewalling
12 Posts 3 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    letuanvn
    last edited by Feb 19, 2020, 1:34 AM

    Thanks for quick feedback! Gertjan

    As you know, Squid Guard is required Certificate to apply rules reject URL and apply blacklist.
    If one PC or mobile have not a Certificate (of Pfsense), it's could not access to internet.
    So, with a PC you can install easily & I wonder about the mobile phone. How I can install CER to mobile phone? (IOS, Android)

    G 1 Reply Last reply Feb 19, 2020, 3:21 AM Reply Quote 0
    • G
      Gertjan @letuanvn
      last edited by Feb 19, 2020, 3:21 AM

      @letuanvn said in How deploy Certificate automation to mobile (IOS, Android) use Squid Proxy?:

      So, with a PC you can install easily & I wonder about the mobile phone. How I can install CER to mobile phone? (IOS, Android)

      That's the core question.
      Guess so .... not sure. But Google showed me that it can be done https://support.quovadisglobal.com/kb/a64/how-do-i-install-a-digital-certificate-onto-an-iphone-or-ipad.aspx
      pfSense can export p12 certs.
      So, mail it up, and instruct the iPhone user.
      It might be wise not to use non-trusted certs. That's where the acme package kicks in, and you'll be needing a domain name.
      Samsung devices : probably also.

      So, actually, it could be done - although not fully automated. But hey, I could be wrong twice today ^^

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • L
        letuanvn
        last edited by Feb 19, 2020, 4:06 AM

        Hi Gertjan,
        Thank you again for your answer!
        I have to refer some Guide on google seem to you. But it's manual to add to the phone.
        I would like to take easy for end users --> Automatic.

        Example: Network Policy Server (NPS) of Microsoft, auto apply certificate when the mobile connect to wifi, end user only hit TRUST the certificate and access internet successfully.

        Many thanks if have more any good for me to process the next step.
        Thanks,
        Tony

        G 1 Reply Last reply Feb 19, 2020, 9:49 AM Reply Quote 0
        • G
          Gertjan @letuanvn
          last edited by Feb 19, 2020, 9:49 AM

          @letuanvn said in How deploy Certificate automation to mobile (IOS, Android) use Squid Proxy?:

          Example: Network Policy Server (NPS) of Microsoft, auto apply certifi

          A notable difference here is : these devices are not owned by the users, they are merely the tools they use to work with. The owner - the company, will state what to do when and how up front.
          Devices used on a captive portal are owned by the users themselves.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • L
            letuanvn
            last edited by Feb 20, 2020, 2:06 AM

            Actually, i would like to protect personal device access to LAN network.
            So, i use Squid Guard and i get the trouble with Mobile Phone. (Can not install Certificate, can not access to internet)

            G 1 Reply Last reply Feb 20, 2020, 10:27 AM Reply Quote 0
            • L
              letuanvn
              last edited by Feb 20, 2020, 9:46 AM

              Anybody can help?

              N 1 Reply Last reply Feb 22, 2020, 5:01 PM Reply Quote 0
              • G
                Gertjan @letuanvn
                last edited by Feb 20, 2020, 10:27 AM

                @letuanvn said in How deploy Certificate automation to mobile (IOS, Android) use Squid Proxy?:

                Mobile Phone

                Well ... for the iPhones/iPad, etc your ok, right ? You saw the link. It's hands-on time now.
                Pretty sure by now that 'the other one' (Samsung) can import certs also.

                Why do you want to protect devices ? With Squid ?
                All traffic is already TLS ... Mobile devices have no open ports (users can't mess them up as they do with their PC's).
                You could even put your AP's in "isolating mode" (something that Windows does as an OS when it asks you if the network is Private or Public).

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • N
                  NollipfSense @letuanvn
                  last edited by NollipfSense Feb 22, 2020, 5:01 PM Feb 22, 2020, 5:01 PM

                  @letuanvn said in How deploy Certificate automation to mobile (IOS, Android) use Squid Proxy?:

                  Anybody can help?

                  You're stubborn...as Gertjan already stated, it won't work...for Samsung, get an OTG cable and transfer the certificate to a jump drive, then connect the drive to the OTG cable and install...for IOS, you can use iTunes or the iCloud or email as that's a closed environment.

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  L 1 Reply Last reply Feb 24, 2020, 2:54 AM Reply Quote 0
                  • L
                    letuanvn @NollipfSense
                    last edited by letuanvn Feb 24, 2020, 2:55 AM Feb 24, 2020, 2:54 AM

                    @NollipfSense Thanks for your feedback!
                    I understood Gertjan mean. But it's a manual action.

                    N 1 Reply Last reply Feb 24, 2020, 3:16 PM Reply Quote 0
                    • N
                      NollipfSense @letuanvn
                      last edited by NollipfSense Feb 24, 2020, 3:16 PM Feb 24, 2020, 3:16 PM

                      @letuanvn said in How deploy Certificate automation to mobile (IOS, Android) use Squid Proxy?:

                      @NollipfSense Thanks for your feedback!
                      I understood Gertjan mean. But it's a manual action.

                      It cannot be done automatically as you're wanting to do.

                      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                      1 Reply Last reply Reply Quote 0
                      12 out of 12
                      • First post
                        12/12
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received