|  02-11-2012, 10:33 PM | #1 | 
| (offline)            Posts: 2,907 Karma: 6736094 Join Date: Dec 2011 Device: K3, K4, K5, KPW, KPW2 | 
				
				[Kindle Touch] Support for Enterprise WPA
			 
			
			UPDATE for Firmware 5.1.0: This has become obsolete with firmware 5.1.0, because that firmware includes support for WPA-EAP. You can run the uninstaller either before, or after, you have updated. Hi all, I have created a launcher extension which allows to connect to Enterprise WPA (aka WPA-EAP) networks. There is no fancy GUI (configuration is via configuration files), but once it is correctly configured, at least you can connect to the network with a single click. Installer/uninstaller files and source code are attached. Last edited by ixtab; 04-12-2012 at 04:47 PM. Reason: Update for 5.1.0 | 
|   |   | 
|  02-12-2012, 09:33 PM | #2 | 
| (offline)            Posts: 2,907 Karma: 6736094 Join Date: Dec 2011 Device: K3, K4, K5, KPW, KPW2 | 
			
			I just found a small glitch in the shell script. If you're using this, please replace extensions/wpa_eap/wpa_eap.sh with the attached one. Note that you can also run this script "interactively" if connected via usbnet, for instance: Code: sh /mnt/us/extensions/wpa_eap/wpa_eap.sh /mnt/us/extensions/wpa_eap/networks/sample.cfg Anyway, can anyone confirm that this is working not only for me? Update: attachment removed, please install version 1.1 from above post. It includes this, and another small fix as well. Last edited by ixtab; 02-13-2012 at 02:12 AM. | 
|   |   | 
| Advert | |
|  | 
|  02-12-2012, 09:44 PM | #3 | |
| hub            Posts: 715 Karma: 2151032 Join Date: Jan 2012 Location: Iranian in Canada Device: K3G, DXG, Kobo mini | Quote: 
  ) but Update is disabled for me! (I know it was discussed in another thread and I gave advice to the poster myself how to figure it out) but can't do it now!!! I even did this: After copying the bin to /mnt/us/, I disabled usbnetworking, unplugged then replugged USB cable so that it goes to USB drive mode. And I tried it when USB is unplugged but still grayed. I wonder if Amazon has updated something in my Touch so no bins can be installed (I haven't tried this). | |
|   |   | 
|  02-12-2012, 10:16 PM | #4 | 
| (offline)            Posts: 2,907 Karma: 6736094 Join Date: Dec 2011 Device: K3, K4, K5, KPW, KPW2 | 
			
			for updates, either: put them on the device via USB drive, then disconnect and use "Update my Kindle" or force an update from the shell: Code: lipc-set-prop com.lab126.ota startUpdate 1 | 
|   |   | 
|  02-13-2012, 01:49 AM | #5 | 
| hub            Posts: 715 Karma: 2151032 Join Date: Jan 2012 Location: Iranian in Canada Device: K3G, DXG, Kobo mini | 
			
			cool ixtab. Thanks. (also I pm'ed you) | 
|   |   | 
| Advert | |
|  | 
|  02-16-2012, 10:03 PM | #6 | 
| Enthusiast            Posts: 46 Karma: 97694 Join Date: Feb 2012 Device: kindle touch | 
			
			did anyone configure this for eduroam already?
		 | 
|   |   | 
|  02-17-2012, 04:56 PM | #7 | |
| hub            Posts: 715 Karma: 2151032 Join Date: Jan 2012 Location: Iranian in Canada Device: K3G, DXG, Kobo mini | Quote: 
 I tried the version 1.0 and refused to work for me. For some reason, I don't want to reboot my Touch, but were your changes in 1.1 significant so that it can work? What were the changes if I shall ask? Last edited by thatworkshop; 02-17-2012 at 04:59 PM. | |
|   |   | 
|  02-18-2012, 02:14 AM | #8 | |
| (offline)            Posts: 2,907 Karma: 6736094 Join Date: Dec 2011 Device: K3, K4, K5, KPW, KPW2 | Quote: 
 "Refused" as in "software crashed and burned" or "refused" as in "I'm not sure if my parameters are correct"? You are strongly encouraged to download the (just produced) version 1.2. If you don't want to install it using "update your Kindle", feel free to extract the contents of the .bin and manually install the files. You are also strongly encouraged to test your configuration from the command line, because it provides potentially useful output. Once it works from the command line, it should also work using the launcher. The changes are: - version 1.1: fixes in wpa_eap.sh ("certificate not yet valid" logic was broken in 1.0, in the sense that it would always set the time to a particular timestamp regardless of the certificate; moreover, output when run from the shell is more useful in 1.1) - version 1.2: fix in the invocation (originally forgot the leading slash of "/mnt/us...", I wonder why it even worked at all before). | |
|   |   | 
|  02-18-2012, 05:02 AM | #9 | 
| Enthusiast            Posts: 44 Karma: 5666 Join Date: Dec 2011 Device: K3-3G, KT SO | 
			
			is there any chance to enable kindle touch to connect to peer-to-peer wifi networks ? can't connect to my wifi router from mobile :/ | 
|   |   | 
|  02-18-2012, 05:31 AM | #10 | 
| (offline)            Posts: 2,907 Karma: 6736094 Join Date: Dec 2011 Device: K3, K4, K5, KPW, KPW2 | 
			
			According to http://linuxwireless.org/en/users/Drivers/ath6kl , the driver (it's called "ar6003" on the Kindle) should in principle support ad-hoc mode. I guess that you will need to find the correct commands to make it do so, my first guess would be iwconfig. If you find out how to do it, feel free to post your results here. Maybe I can include them in the file, so this could become an "enable officially unsupported Wireless modes" utility instead of an "enable WPA-EAP Wireless mode" utility only. | 
|   |   | 
|  02-21-2012, 05:52 AM | #11 | 
| Member            Posts: 10 Karma: 2602 Join Date: Jan 2012 Device: Kindle Touch |  Configuration for eduroam 
			
			Just did :-). This is configuration for Eduroam at MFF UK, Czech Republic. (eduroam.cuni.cz). It should work for other universities too. Tested on Kindle Touch 5.0.3 with package 1.2. this is my eduroam.cfg: Code: ssid eduroam scan_ssid 1 key_mgmt WPA-EAP pairwise CCMP group TKIP eap PEAP identity "12345678@cuni.cz" password "****************" anonymous_identity "@cuni.cz" altsubject_match "DNS:radius1.eduroam.cuni.cz;DNS:radius2.eduroam.cuni.cz" phase1 "peaplabel=0" phase2 "auth=MSCHAPV2" Running 'iwlist scan' from your Kindle (or nearby Linux computer with WiFi) should give you the values for encryption ciphers (group, pairwise). There seem to be multiple CA certificates used at different universities. If you can't find those provided by your university, try one of the attached ones. UVT-89-version1-UTN (Terena CA) worked for me. Save the certificate as eduroam.pem . Last edited by matejs; 02-29-2012 at 09:00 AM. Reason: removed = from anonymous_identity, added info about iwlist scan | 
|   |   | 
|  02-21-2012, 12:13 PM | #12 | |
| Enthusiast            Posts: 44 Karma: 5666 Join Date: Dec 2011 Device: K3-3G, KT SO | Quote: 
 iwconfig wlan0 mode ad-hoc but every try to connect to my ad-hoc network resulted in reverting back to managed mode and autoconnection to my wifi router ;/ | |
|   |   | 
|  02-21-2012, 05:44 PM | #13 | 
| Enthusiast            Posts: 46 Karma: 97694 Join Date: Feb 2012 Device: kindle touch | 
			
			thank you matejs, I will test that as soon as I'm back at my university and then post my results here | 
|   |   | 
|  02-28-2012, 03:22 PM | #14 | 
| Member  Posts: 11 Karma: 10 Join Date: Feb 2012 Device: Kindle Touch | 
			
			I have tryed this for eduroam germany, but it doesn´t work: eduroam.cfg: ssid eduroam scan_ssid 1 key_mgmt WPA-EAP eap TTLS identity "XXXXX@uni-giessen.de" anonymous_identity="anonymous@uni-giessen.de" password "XXXXXXXX" phase2 "auth=PAP" eduroam.pem: -----BEGIN CERTIFICATE----- MIIDnzCCAoegAwIBAgIBJjANBgkqhkiG9w0BAQUFADBxMQswCQ YDVQQGEwJERTEc MBoGA1UEChMTRGV1dHNjaGUgVGVsZWtvbSBBRzEfMB0GA1UECx MWVC1UZWxlU2Vj IFRydXN0IENlbnRlcjEjMCEGA1UEAxMaRGV1dHNjaGUgVGVsZW tvbSBSb290IENB IDIwHhcNOTkwNzA5MTIxMTAwWhcNMTkwNzA5MjM1OTAwWjBxMQ swCQYDVQQGEwJE RTEcMBoGA1UEChMTRGV1dHNjaGUgVGVsZWtvbSBBRzEfMB0GA1 UECxMWVC1UZWxl U2VjIFRydXN0IENlbnRlcjEjMCEGA1UEAxMaRGV1dHNjaGUgVG VsZWtvbSBSb290 IENBIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQ CrC6M14IspFLEU ha88EOQ5bzVdSq7d6mGNlUn0b2SjGmBmpKlAIoTZ1KXleJMOaA GtuU1cOs7TuKhC QN/Po7qCWWqSG6wcmtoIKyUn+WkjR/Hg6yx6m/UTAtB+NHzCnjwAWav12gz1Mjwr rFDa1sPeg5TKqAyZMg4ISFZbavva4VhYAUlfckE8FQYBjl2tqr iTtM2e66foai1S NNs671x1Udrb8zH57nGYMsRUFUQM+ZtV7a3fGAigo4aKSe5TBY 8ZTNXeWHmb0moc QqvF1afPaA+W5OFhmHZhyJF81j4A4pFQh+GdCuatl9Idxjp9y7 zaAzTVjlsB9WoH txa2bkp/AgMBAAGjQjBAMB0GA1UdDgQWBBQxw3kbuvVT1xfgiXotF2wKsy udMzAP BgNVHRMECDAGAQH/AgEFMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQUFAAOC AQEAlGRZrTlk5ynrE/5aw4sTV8gEJPB0d8Bg42f76Ymmg7+Wgnxu1MM9756Abrsp tJh6sTtU6zkXR34ajgv8HzFZMQSyzhfzLMdiNlXiItiJVbSYSK pk+tYcNthEeFpa IzpXl/V6ME+un2pMSyuOoAPjPuCp1NJ70rOo4nI8rZ7/gFnkm0W09juwzTkZmDLl 6iFhkOQxIY40sfcvNUqFENrnijchvllj4PKFiDFT1FQUhXB59C 4Gdyd1Lx+4ivn+ xbrYNuSD7Odlt79jWvNGr4GUN9RBjNYj1h7P9WgbRGOiWrqnNV mh5XAFmw4jV5mU Cm26OWMohpLzGITY+9HPBVZkVw== -----END CERTIFICATE----- anybody some ideas? | 
|   |   | 
|  02-28-2012, 05:17 PM | #15 | 
| (offline)            Posts: 2,907 Karma: 6736094 Join Date: Dec 2011 Device: K3, K4, K5, KPW, KPW2 | 
			
			The parameters look correct as far as I can tell (comparing with http://fss.plone.uni-giessen.de/fss/...upplicant.conf). One line looks suspicious though: anonymous_identity="anonymous@uni-giessen.de" I'm not sure if it should contain the "=" sign. Try running the script from the command line (see my second or third post) and check the output, and possibly remove the = and check again. Good luck   | 
|   |   | 
|  | 
| 
 | 
|  Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post | 
| Kindle 3 WPA Supplicant | omka88 | Kindle Developer's Corner | 72 | 02-01-2013 07:44 AM | 
| Kindle Touch PDF support | tomsem | Amazon Kindle | 7 | 12-07-2011 11:56 AM | 
| WPA 2 Enterprise support? | Deonna_White | enTourage Archive | 6 | 04-14-2010 05:58 PM | 
| iLiad Undocumented WPA support with iLiad 2.9 firmware - how to enable it | Alexander Turcic | iRex Developer's Corner | 7 | 03-08-2007 07:02 PM |