Android 11 - How to connect to a WPA2 Enterprise EAP PEAP using WifiNetworkSuggestion?

Viewed 472

I'm developing an app to connect to WPA2 Enterprise EAP PEAP networks so that the user doesn't have to enter his credentials.

For Android 11 devices, I'm using WifiNetworkSuggestion as I think is the best available option. The problem is that when I try to connect, this exception is thrown:

java.lang.IllegalArgumentException: Enterprise configuration is insecure at kotlin.coroutines.jvm.internal.BaseContinuationImpl.resumeWith(ContinuationImpl.kt:33) at android.net.wifi.WifiNetworkSuggestion$Builder.setWpa2EnterpriseConfig(WifiNetworkSuggestion.java:275)

This is how I initialize the configuration:

    private fun initWpa2EnterpriseWifiSuggestion(wifiConnection: WifiConnectionEntity) =
        if (wifiConnection.user != null && wifiConnection.password != null) {
            val networkSuggestionBuilder = WifiNetworkSuggestion.Builder()
            networkSuggestionBuilder.setSsid(wifiConnection.ssid)

            if (wifiConnection.sharedKey != null) {
                networkSuggestionBuilder.setWpa2Passphrase(wifiConnection.sharedKey)
            }

            val enterpriseConfig = WifiEnterpriseConfig()
            enterpriseConfig.identity = wifiConnection.user
            enterpriseConfig.password = wifiConnection.password
            enterpriseConfig.eapMethod = WifiEnterpriseConfig.Eap.PEAP
            enterpriseConfig.phase2Method = WifiEnterpriseConfig.Phase2.MSCHAPV2
            networkSuggestionBuilder.setWpa2EnterpriseConfig(enterpriseConfig)

            Pair(networkSuggestionBuilder.build(), null)
        } else {
            Pair(
                null,
                if (wifiConnection.user != null) ERROR_USER_NOT_PROVIDED else ERROR_PASSWORD_NOT_PROVIDED
            )
        }

And I launch the suggestion with:

val wifiManager = appContext.getSystemService(Context.WIFI_SERVICE) as WifiManager
                val status = wifiManager.addNetworkSuggestions(listOf(wifiSuggestion.first))

                if (status != WifiManager.STATUS_NETWORK_SUGGESTIONS_SUCCESS) {
                    trySend(WifiManagementDataResult.Error(null, ERROR_NETWORK_SUGGESTION))

                } else {
                    trySend(WifiManagementDataResult.Success(null, null))

I have been reading in https://developer.android.com/guide/topics/connectivity/wifi-suggest that I need to specify the ca certificates (setCaCertificate method) and the server domain name (setAltSubjectMatch method).

I haven't found too much information about it: CA certificates must be included as resources of the app and convert them to X509Certificate models? Has anyone connected in any other way?

Any help would be appreciated.

Update: I have been able to connect to the network manually, in device Settings. The option "No certificates" appears and I read that this option was removed in Android 11. Is there any way to use "No certificates" option with WifiNetworkSuggestion?

Update 2: With the method public WifiNetworkSuggestion.Builder setUntrusted (boolean isUntrusted), "Enterprise configuration is insecure" exception is not thrown and the network suggestion dialog appears. However, the device does not connect to the network and the configuration is not saved in the operating system.

Update 3: I have been testing in another network and despite using public WifiNetworkSuggestion.Builder setUntrusted (boolean isUntrusted), the exception is thrown. I don't know why last time it didn't throw.

0 Answers
Related