![]() |
#1 |
(offline)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,907
Karma: 6736094
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
|
[Kindle Touch] Support for Enterprise WPA
UPDATE for Firmware 5.1.0: This has become obsolete with firmware 5.1.0, because that firmware includes support for WPA-EAP. You can run the uninstaller either before, or after, you have updated.
Hi all, I have created a launcher extension which allows to connect to Enterprise WPA (aka WPA-EAP) networks. There is no fancy GUI (configuration is via configuration files), but once it is correctly configured, at least you can connect to the network with a single click. Installer/uninstaller files and source code are attached. Last edited by ixtab; 04-12-2012 at 04:47 PM. Reason: Update for 5.1.0 |
![]() |
![]() |
![]() |
#2 |
(offline)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,907
Karma: 6736094
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
|
I just found a small glitch in the shell script. If you're using this, please replace extensions/wpa_eap/wpa_eap.sh with the attached one.
Note that you can also run this script "interactively" if connected via usbnet, for instance: Code:
sh /mnt/us/extensions/wpa_eap/wpa_eap.sh /mnt/us/extensions/wpa_eap/networks/sample.cfg Anyway, can anyone confirm that this is working not only for me? Update: attachment removed, please install version 1.1 from above post. It includes this, and another small fix as well. Last edited by ixtab; 02-13-2012 at 02:12 AM. |
![]() |
![]() |
![]() |
#3 | |
hub
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 715
Karma: 2151032
Join Date: Jan 2012
Location: Iranian in Canada
Device: K3G, DXG, Kobo mini
|
Quote:
![]() I even did this: After copying the bin to /mnt/us/, I disabled usbnetworking, unplugged then replugged USB cable so that it goes to USB drive mode. And I tried it when USB is unplugged but still grayed. I wonder if Amazon has updated something in my Touch so no bins can be installed (I haven't tried this). |
|
![]() |
![]() |
![]() |
#4 |
(offline)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,907
Karma: 6736094
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
|
for updates, either:
put them on the device via USB drive, then disconnect and use "Update my Kindle" or force an update from the shell: Code:
lipc-set-prop com.lab126.ota startUpdate 1 |
![]() |
![]() |
![]() |
#5 |
hub
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 715
Karma: 2151032
Join Date: Jan 2012
Location: Iranian in Canada
Device: K3G, DXG, Kobo mini
|
cool ixtab. Thanks.
(also I pm'ed you) |
![]() |
![]() |
![]() |
#6 |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 46
Karma: 97694
Join Date: Feb 2012
Device: kindle touch
|
did anyone configure this for eduroam already?
|
![]() |
![]() |
![]() |
#7 | |
hub
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 715
Karma: 2151032
Join Date: Jan 2012
Location: Iranian in Canada
Device: K3G, DXG, Kobo mini
|
Quote:
I tried the version 1.0 and refused to work for me. For some reason, I don't want to reboot my Touch, but were your changes in 1.1 significant so that it can work? What were the changes if I shall ask? Last edited by thatworkshop; 02-17-2012 at 04:59 PM. |
|
![]() |
![]() |
![]() |
#8 | |
(offline)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,907
Karma: 6736094
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
|
Quote:
"Refused" as in "software crashed and burned" or "refused" as in "I'm not sure if my parameters are correct"? You are strongly encouraged to download the (just produced) version 1.2. If you don't want to install it using "update your Kindle", feel free to extract the contents of the .bin and manually install the files. You are also strongly encouraged to test your configuration from the command line, because it provides potentially useful output. Once it works from the command line, it should also work using the launcher. The changes are: - version 1.1: fixes in wpa_eap.sh ("certificate not yet valid" logic was broken in 1.0, in the sense that it would always set the time to a particular timestamp regardless of the certificate; moreover, output when run from the shell is more useful in 1.1) - version 1.2: fix in the invocation (originally forgot the leading slash of "/mnt/us...", I wonder why it even worked at all before). |
|
![]() |
![]() |
![]() |
#9 |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 44
Karma: 5666
Join Date: Dec 2011
Device: K3-3G, KT SO
|
is there any chance to enable kindle touch to connect to peer-to-peer wifi networks ?
can't connect to my wifi router from mobile :/ |
![]() |
![]() |
![]() |
#10 |
(offline)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,907
Karma: 6736094
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
|
According to http://linuxwireless.org/en/users/Drivers/ath6kl , the driver (it's called "ar6003" on the Kindle) should in principle support ad-hoc mode. I guess that you will need to find the correct commands to make it do so, my first guess would be iwconfig.
If you find out how to do it, feel free to post your results here. Maybe I can include them in the file, so this could become an "enable officially unsupported Wireless modes" utility instead of an "enable WPA-EAP Wireless mode" utility only. |
![]() |
![]() |
![]() |
#11 |
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 10
Karma: 2602
Join Date: Jan 2012
Device: Kindle Touch
|
![]()
Just did :-).
This is configuration for Eduroam at MFF UK, Czech Republic. (eduroam.cuni.cz). It should work for other universities too. Tested on Kindle Touch 5.0.3 with package 1.2. this is my eduroam.cfg: Code:
ssid eduroam scan_ssid 1 key_mgmt WPA-EAP pairwise CCMP group TKIP eap PEAP identity "12345678@cuni.cz" password "****************" anonymous_identity "@cuni.cz" altsubject_match "DNS:radius1.eduroam.cuni.cz;DNS:radius2.eduroam.cuni.cz" phase1 "peaplabel=0" phase2 "auth=MSCHAPV2" Running 'iwlist scan' from your Kindle (or nearby Linux computer with WiFi) should give you the values for encryption ciphers (group, pairwise). There seem to be multiple CA certificates used at different universities. If you can't find those provided by your university, try one of the attached ones. UVT-89-version1-UTN (Terena CA) worked for me. Save the certificate as eduroam.pem . Last edited by matejs; 02-29-2012 at 09:00 AM. Reason: removed = from anonymous_identity, added info about iwlist scan |
![]() |
![]() |
![]() |
#12 | |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 44
Karma: 5666
Join Date: Dec 2011
Device: K3-3G, KT SO
|
Quote:
iwconfig wlan0 mode ad-hoc but every try to connect to my ad-hoc network resulted in reverting back to managed mode and autoconnection to my wifi router ;/ |
|
![]() |
![]() |
![]() |
#13 |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 46
Karma: 97694
Join Date: Feb 2012
Device: kindle touch
|
thank you matejs,
I will test that as soon as I'm back at my university and then post my results here |
![]() |
![]() |
![]() |
#14 |
Member
![]() Posts: 11
Karma: 10
Join Date: Feb 2012
Device: Kindle Touch
|
I have tryed this for eduroam germany, but it doesn´t work:
eduroam.cfg: ssid eduroam scan_ssid 1 key_mgmt WPA-EAP eap TTLS identity "XXXXX@uni-giessen.de" anonymous_identity="anonymous@uni-giessen.de" password "XXXXXXXX" phase2 "auth=PAP" eduroam.pem: -----BEGIN CERTIFICATE----- MIIDnzCCAoegAwIBAgIBJjANBgkqhkiG9w0BAQUFADBxMQswCQ YDVQQGEwJERTEc MBoGA1UEChMTRGV1dHNjaGUgVGVsZWtvbSBBRzEfMB0GA1UECx MWVC1UZWxlU2Vj IFRydXN0IENlbnRlcjEjMCEGA1UEAxMaRGV1dHNjaGUgVGVsZW tvbSBSb290IENB IDIwHhcNOTkwNzA5MTIxMTAwWhcNMTkwNzA5MjM1OTAwWjBxMQ swCQYDVQQGEwJE RTEcMBoGA1UEChMTRGV1dHNjaGUgVGVsZWtvbSBBRzEfMB0GA1 UECxMWVC1UZWxl U2VjIFRydXN0IENlbnRlcjEjMCEGA1UEAxMaRGV1dHNjaGUgVG VsZWtvbSBSb290 IENBIDIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQ CrC6M14IspFLEU ha88EOQ5bzVdSq7d6mGNlUn0b2SjGmBmpKlAIoTZ1KXleJMOaA GtuU1cOs7TuKhC QN/Po7qCWWqSG6wcmtoIKyUn+WkjR/Hg6yx6m/UTAtB+NHzCnjwAWav12gz1Mjwr rFDa1sPeg5TKqAyZMg4ISFZbavva4VhYAUlfckE8FQYBjl2tqr iTtM2e66foai1S NNs671x1Udrb8zH57nGYMsRUFUQM+ZtV7a3fGAigo4aKSe5TBY 8ZTNXeWHmb0moc QqvF1afPaA+W5OFhmHZhyJF81j4A4pFQh+GdCuatl9Idxjp9y7 zaAzTVjlsB9WoH txa2bkp/AgMBAAGjQjBAMB0GA1UdDgQWBBQxw3kbuvVT1xfgiXotF2wKsy udMzAP BgNVHRMECDAGAQH/AgEFMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQUFAAOC AQEAlGRZrTlk5ynrE/5aw4sTV8gEJPB0d8Bg42f76Ymmg7+Wgnxu1MM9756Abrsp tJh6sTtU6zkXR34ajgv8HzFZMQSyzhfzLMdiNlXiItiJVbSYSK pk+tYcNthEeFpa IzpXl/V6ME+un2pMSyuOoAPjPuCp1NJ70rOo4nI8rZ7/gFnkm0W09juwzTkZmDLl 6iFhkOQxIY40sfcvNUqFENrnijchvllj4PKFiDFT1FQUhXB59C 4Gdyd1Lx+4ivn+ xbrYNuSD7Odlt79jWvNGr4GUN9RBjNYj1h7P9WgbRGOiWrqnNV mh5XAFmw4jV5mU Cm26OWMohpLzGITY+9HPBVZkVw== -----END CERTIFICATE----- anybody some ideas? |
![]() |
![]() |
![]() |
#15 |
(offline)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,907
Karma: 6736094
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
|
The parameters look correct as far as I can tell (comparing with http://fss.plone.uni-giessen.de/fss/...upplicant.conf).
One line looks suspicious though: anonymous_identity="anonymous@uni-giessen.de" I'm not sure if it should contain the "=" sign. Try running the script from the command line (see my second or third post) and check the output, and possibly remove the = and check again. Good luck ![]() |
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Kindle 3 WPA Supplicant | omka88 | Kindle Developer's Corner | 72 | 02-01-2013 07:44 AM |
Kindle Touch PDF support | tomsem | Amazon Kindle | 7 | 12-07-2011 11:56 AM |
WPA 2 Enterprise support? | Deonna_White | enTourage Archive | 6 | 04-14-2010 05:58 PM |
iLiad Undocumented WPA support with iLiad 2.9 firmware - how to enable it | Alexander Turcic | iRex Developer's Corner | 7 | 03-08-2007 07:02 PM |