Onboard an iPhone to a Wi-Fi network with certificates
In this topic, you will learn how to onboard using certificates, the self-onboarding portal, an iPhone with iOS, and a Wi-Fi network managed by Portnox™ Cloud.
To onboard to a network using a certificate, you need to generate, download, and install the user/device certificate, and then configure your operating system to connect to the network using this certificate. You can configure your operating system semi-automatically using provisioning or manually.
If you already downloaded and installed the certificate for the same device, for example, to authenticate with another type of network, you don’t need to install the certificate again and you should skip the relevant steps.
Download and install the certificate
In this section, you will generate, download, and install the user certificate on your device.
-
Enter the URL of the self-onboarding portal in your browser.
To learn how to set up the self-onboarding portal and obtain the URL, see the following topic: Set up the self-onboarding portal.
-
In Step 1, select the third option: CLEAR account certificate
management and press the Next button.
- In Step 2, you can select the Corporate email address option or the Corporate username and password option. Select the Corporate email address option if Portnox Cloud manages your user repository. Select the Corporate username and password option if you have integrated Cloud with an external repository. Proceed with the following steps depending on your choice.
-
If you have chosen Corporate email address:
Important: Only choose the Corporate email address option if Portnox Cloud manages your user repository. Cloud manages the user repository if it’s not integrated with any external repositories such as Microsoft Azure (Entra ID), Google Workspace, or Okta Workforce Identity.
-
If you have chosen Corporate username and password:
-
Press the OBTAIN CERTIFICATE button to download the user certificate generated for your
device.
Note: If you want to replace a certificate you created earlier, for example, because the old one expires soon, press the REISSUE CERTIFICATE button instead.
-
In the pop-up that says The website is trying to download a configuration profile, press
Allow.
-
In the Profile Downloaded pop-up, press Close.
-
Press the Home button and press the icon of the Settings app.
-
In the Settings app, press the Profile Downloaded row.
-
In the Install Profile pane, press Install.
-
Enter your passcode.
-
Press Install.
Result: You downloaded and installed the certificate.
Configure the connection with provisioning
In this section, you will use the self-onboarding portal to generate a provisioning profile that configures your network for you.
You only need to configure your network once so if you do the steps in this section, you should skip the next section.
- Go back to Step 1 of the self-onboarding portal by clicking on the Back link.
-
In Step 1, select the second option: CLEAR account activation and Device
provisioning and press the Next button.
Important: The Wi-Fi network in the group that the account belongs to must be configured for EAP-TLS authentication. For more information, see the following topic: Advanced network configuration.
- Follow the same steps as above to authenticate using your corporate email or corporate username and password.
-
Press the tile in the Wireless Enrollment Profile section that represents the iOS operating
system to download the provisioning profile.
-
In the pop-up that says The website is trying to download a configuration profile, press
Allow.
-
In the Profile Downloaded pop-up, press Close.
-
Press the Home button and press the icon of the Settings app.
-
In the Settings app, press the Profile Downloaded row.
-
In the Install Profile pane, press Install.
-
Enter your passcode.
-
Press Install.
-
Go back to the Settings app and press the Wi-Fi row to change the Wi-Fi settings.
-
Press the configured Wi-Fi network in the MY NETWORKS section to connect.
Result: Your iPhone phone is connected to a Wi-Fi network managed by Portnox Cloud.
Troubleshooting information: See the following topic: How to troubleshoot typical device onboarding issues.
Configure the connection manually
In this section, you will manually configure your network to use the installed certificate.
You only need to configure your network once so if you did the steps in the previous section, you should skip this section.
-
Press the Home button and press the icon of the Settings app.
-
In the settings app, press the Wi-Fi row to change the Wi-Fi settings.
-
In the NETWORKS section, press the name of the network to configure.
-
In the Enter Password pane, press the Mode row to change the connection
mode.
-
In the Security pane, press EAP-TLS to select it and then press
Enter Password to go back to the previous pane.
-
In the Enter Password pane, enter your corporate email address as
Username and press the Identity row to select the identity.
-
In the Identity pane, press your Portnox identity imported with the certificate to select it
and then press Enter Password to go back to the previous pane.
-
Press Join to connect to the network.
Result: Your iPhone phone is connected to a Wi-Fi network managed by Portnox Cloud.
Troubleshooting information: See the following topic: How to troubleshoot typical device onboarding issues.