Security Basics mailing list archives

Re: Wireless solutions with multiple keys


From: "Morgan Reed" <morgan.s.reed () gmail com>
Date: Fri, 12 Dec 2008 11:02:56 +1100

On Fri, Dec 12, 2008 at 9:10 AM, Nick Duda <nduda () vistaprint com> wrote:
Thanks for the info. I actually run a Wireless network using wpa2 and ad authentication for local lan users, it works 
great. The issue here is that I want to make a new wifi lan that anyone can use only if they are authenticated...but 
this authentication needs to be automated somehow. When I say "anyone can use it" I mean that anyone that has access 
to something that can tell them the key to get on. I guess what I am saying is that I want a wifi network in the 
workplace that a wardriver cannot just "jump on", but any employee can because they can pull up on an intranet site 
"This weeks key". If the employee is working on a weekend and brings their spouse in with a laptop, that employee 
just look at what "This weeks key" is and configures it on the spouse laptop.

Resending because I forgot to reply to the list.

Does it have to be managed by WPA keys?

In this sort of scenario I'd setup a modified captive portal on an
unencrypted network. Have access restricted to the portal site and
your intranet page (which I assume has authentication wrapped around
it), intranet page gives them the daily/weekly/whatever password to
access the portal, they use the password to access the portal, they
get out.


Current thread: