Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    eap-tls on apple watch?

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    16 Posts 4 Posters 86 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • tinfoilmattT Offline
      tinfoilmatt @johnpoz
      last edited by tinfoilmatt

      @johnpoz Appears to definitely be possible: https://developer.apple.com/documentation/devicemanagement/wifi/eapclientconfiguration-data.dictionary

      I've used iMazing Profile Editor before to create valid configuration profiles (like to create a pfSense-hosted IPsec mobile warrior VPN on an iPhone, for example).

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator @tinfoilmatt
        last edited by

        @tinfoilmatt yeah I have Imazing - and they added watch stuff, but only on their version that runs on mac0S. I can't get it to see my watch.

        Atleast that is how I was reading it - might have to take a closer look at look at their profile editor..

        imazing.jpg

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        tinfoilmattT 1 Reply Last reply Reply Quote 0
        • tinfoilmattT Offline
          tinfoilmatt @johnpoz
          last edited by

          @johnpoz It does, in fact, contain all dictionaries (including WiFi.EAPClientConfiguration) for all supported OSes.

          c83e9d70-c604-46bb-ac3c-a0baadc04b8a-image.png

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator @tinfoilmatt
            last edited by

            @tinfoilmatt ok how do you now get it on your watch??

            I have added the certs, put in the ssid, etc. and have a mobileconfig file - how do you you get it onto the watch?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            tinfoilmattT GertjanG 2 Replies Last reply Reply Quote 0
            • tinfoilmattT Offline
              tinfoilmatt @johnpoz
              last edited by

              @johnpoz Great question. USB charging/data connection cable?

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator @tinfoilmatt
                last edited by johnpoz

                @tinfoilmatt apple watches don't have those ;) at least not newer ones.. I can't see how to get normal iamazing to see my watch.. with the iphone I just emailed it to myself and it asked if wanted to load the profile but that was just a p12 file.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                tinfoilmattT 1 Reply Last reply Reply Quote 0
                • tinfoilmattT Offline
                  tinfoilmatt @johnpoz
                  last edited by

                  @johnpoz iMazing (not Profile Editor) has some automagic network discovery functionality. I wonder if it could be used to import a profile to the watch.

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator @tinfoilmatt
                    last edited by

                    @tinfoilmatt If so don't know how to do it - the imazing did add ipad and watch os, but says only for macOS

                    It really shouldn't be this difficult - why can it not just pull the info it needs from my iphone ;)

                    It sees my iphone no problem, but I am not seeing anything about my watch in it.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                    tinfoilmattT 1 Reply Last reply Reply Quote 0
                    • tinfoilmattT Offline
                      tinfoilmatt @johnpoz
                      last edited by

                      I hear you. My next watch will be a Garmin. It definitely won't be able to do EAP-TLS. But I will have much more control over what networks it connects to, and Garmin Express appears to be at least partially supported on Linux.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator @tinfoilmatt
                        last edited by

                        @tinfoilmatt going put this on a back burner - it just ticks me off, when it should be so simple..

                        I mean your watch pulls apps and all sorts of other things from the phone its paired with - why would it also just pull or could be allowed to pull a profile for the certs for connecting to eap-tls..

                        Maybe I will just remove the whole eap-tls option, so its not haunting me every time my phone connects to it and my watch can't ;) hehehe

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                        1 Reply Last reply Reply Quote 0
                        • JonathanLeeJ Online
                          JonathanLee
                          last edited by

                          This isn’t really related to the post, but I wanted to share something. I love Apple products — they’re my go-to when I just want things to work without hassle. I have my setup configured to auto-proxy so I can switch between a secure proxied network and a guest network for testing.
                          After upgrading my iMac to macOS Tahoe, though, it suddenly required a WPAD file even on the non-proxy guest network. I ended up putting a WPAD file on OpenWrt that basically tells the system “there is no proxy.” Once I did that, I could switch between the networks normally again. That way I could leave it on auto proxy.

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • GertjanG Online
                            Gertjan @johnpoz
                            last edited by

                            @johnpoz said in eap-tls on apple watch?:

                            Ok how do you now get it on your watch??

                            Maybe this.

                            Can the watch reveive mails ? If so, if you can send a mail with attached 'config' files that you 'open', and iOS recognized them as config stuff, and now it get flagged under "Settings" and you'll be guided from there ?!
                            I know this works with importing certificats on an iPhone.

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ Offline
                              johnpoz LAYER 8 Global Moderator @Gertjan
                              last edited by johnpoz

                              @Gertjan first thing I tried - can't do anything with the attachment. You can see the email has an attachment, but you can't click it, can't save it.. Unless I am just stupid ;) But can't see anyway to do anything with the attachment on the watch.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG Online
                                Gertjan @johnpoz
                                last edited by

                                @johnpoz
                                Bummer. I down 👎 myself.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • johnpozJ Offline
                                  johnpoz LAYER 8 Global Moderator @Gertjan
                                  last edited by

                                  @Gertjan heheh - thanks for trying.. Its paired to the phone, why can I not just push it from the phone like you can do with an app.. Maybe you can, and just don't know how? And my google is failing - or there just isn't a way, only thing I find is management through the apple stuff like mdm.. But I don't need something for an enterprise or even a smb..

                                  I just want a free way to get eap-tls working on my stupid watch ;)

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.