Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Last revisionBoth sides next revision
en:verejne:sit:wi-fi:linux [07.09.2019 21:48] – [Ubuntu, NetworkManager] finished the translation Pavel Valachen:verejne:sit:wi-fi:linux [25.09.2021 16:33] – [Ubuntu, NetworkManager] Pavel Valach
Line 1: Line 1:
-FIXME **This page is not fully translated, yet. Please help completing the translation.**\\ //(remove this paragraph once the translation is finished)// +====== Set up Wi-Fi on Linux – Ubuntu, NetworkManager, wpa_supplicant ======
- +
-====== Set up Wi-Fi on Linux Ubuntu, NetworkManager, wpa_supplicant ======+
  
 ===== Ubuntu, NetworkManager ===== ===== Ubuntu, NetworkManager =====
Line 21: Line 19:
        * **Security**: WPA2-Enterprise        * **Security**: WPA2-Enterprise
        * **Authentication**: Tunneled TLS        * **Authentication**: Tunneled TLS
-       * **Anonymous identity**: you may leave the field blank or fill out ''anonymous@sin.cvut.cz''+       * **Anonymous identity**: ''anonymous@sin.cvut.cz''
        * **Domain**: ''radius.sin.cvut.cz''        * **Domain**: ''radius.sin.cvut.cz''
-       * **CA certificate**: [[en:verejne:sit:cert|download and save it]] (**DigiCert Assured ID Root CA**, format PEM)+       * **CA certificate**: either browse to ''/etc/ssl/certs/Comodo_AAA_Services_root.pem'', or [[en:verejne:sit:cert|download and save it]] (download format PEM)
        * **Inner authentication**: PAP        * **Inner authentication**: PAP
-       * **Username** and **Password** is the same as your SINIS login. \\ You may also use the SIN email address, which you will find right after logging in to SINIS. \\ {{:en:verejne:sit:wi-fi:ubuntu-nm-profile-sec.png?nolink|}}+       * **Username**: use your SIN username or SIN email (find it after logging in to [[https://sinis.sin.cvut.cz|SINIS]]) 
 +       **Password**the same as for your SINIS login. \\ {{:en:verejne:sit:wi-fi:ubuntu-nm-profile-sec.png?nolink|}}
      * Confirm your settings by pushing the **Save** button.      * Confirm your settings by pushing the **Save** button.
 +
 +<note important>The picture has the certificate wrong! It's for illustration purposes only.</note>
  
 Now, your connection should be all set for secure Wi-Fi browsing. Now, your connection should be all set for secure Wi-Fi browsing.
Line 32: Line 33:
 ===== wpa_supplicant ===== ===== wpa_supplicant =====
  
-WPA Supplicant je program, který se v Linuxu stará o podporu WPA zabezpečení Wi-Fi sítí. NetworkManager interně používá právě wpa_supplicant.+WPA Supplicant is an utility which enables WPA security support for Wi-Fi in Linux. NetworkManager uses wpa_supplicant internally.
  
-Pokud chcete používat tuto variantuníže naleznete ukázku definice sítě Sincoolka. Dále postupujte jako u nastavení eduroamu na stránkách CESNETu: https://www.eduroam.cz/cs/uzivatel/sw/nix/wpa_supplicant+In case you want to set up a wpa_supplicant profile manuallywe have prepared a Sincoolka network definition below
  
-Také si [[verejne:sit:cert|stáhněte]] **certifikát CA** (**DigiCert Assured ID Root CA**, formát PEM) a uložte na přístupné místoCestu k němu později zadáte do konfiguračního souboru. +Please [[en:verejne:sit:cert|download the proper **CA certificate** first]] and save itYou will enter the path to this file in the wpa_supplicant configuration profile.
- +
-Ukázka konfiguračního souboru pro WPA Supplicant:+
  
 <file wpa_supplicant wpa_supplicant.conf> <file wpa_supplicant wpa_supplicant.conf>
 network={ network={
-    ssid="Sincoolka" nebo Sincoolka 5G+    ssid="Sincoolka" or Sincoolka 5G
     scan_ssid=1     scan_ssid=1
     key_mgmt=WPA-EAP     key_mgmt=WPA-EAP
     eap=TTLS     eap=TTLS
-    # cesta ke stazenemu CA certifikatu +    # path to the downloaded CA certificate 
-    ca_cert="/etc/cert/digicert-ca.pem"+    ca_cert="/etc/cert/sin-wifi-ca.pem"
     domain_match="radius.sin.cvut.cz"     domain_match="radius.sin.cvut.cz"
     phase2="auth=PAP"     phase2="auth=PAP"
Line 53: Line 52:
     group=CCMP     group=CCMP
          
-    # Vase uzivatelske udaje+    # Your credentials
     identity="jiri.novak@sin.cvut.cz"     identity="jiri.novak@sin.cvut.cz"
     anonymous_identity="anonymous@sin.cvut.cz"     anonymous_identity="anonymous@sin.cvut.cz"
-    password="VaseSilneHeslo"+    password="YourStr0ngPa$$word"
 } }
 </file> </file>
  
 +===== iwd =====
  
 +//Contributed by our member Artem Poliakov (poliaart <at> fit.cvut.cz)! Thanks!//
 +
 +[[https://iwd.wiki.kernel.org/|iwd]] is a wireless daemon for Linux which aims to utilize features provided by the Linux Kernel to the maximum extent
 +possible. It can work in standalone mode or in combination with comprehensive network managers.
 +
 +If you want to connect to Wi-Fi using iwd, you need to place file called ''Sincoolka.8021x'' or ''Sincoolka 5G.8021x''
 +(depending on which network you'd like to connect) under ''/var/lib/iwd'' directory. The suggested contents can be found below.
 +
 +Please [[en:verejne:sit:cert|download the proper CA certificate first]] and save it. You will enter the path to this file in the iwd configuration profile.
 +
 +<file iwd Sincoolka 5G.8021x>
 +[Security]
 +EAP-Method=TTLS
 +EAP-Identity=anonymous@sin.cvut.cz
 +EAP-TTLS-ServerDomainMask=radius.sin.cvut.cz
 +EAP-TTLS-CACert=/etc/cert/downloaded-ca-certificate.pem
 +EAP-TTLS-Phase2-Method=Tunneled-PAP
 +EAP-TTLS-Phase2-Identity=your.username@sin.cvut.cz
 +EAP-TTLS-Phase2-Password=YourStr0ngPa$$word
 +
 +[Settings]
 +AutoConnect=true
 +</file>
  • en/verejne/sit/wi-fi/linux.txt
  • Last modified: 30.09.2023 11:39
  • by Pavel Valach