Configuring the Chrome Extension on Google Admin Console

On the Google admin console, you can upload certificates, set up the Wi-fi network, add the Cloudpath certificate generator, and set any desired policies for managed Chromebook devices.

Log in to the Google admin console using your Google administrator account (not your Google developer's account).

Uploading Certificates

To upload certificates, do the following:

  1. Go to Devices > Networks > Certificates.
  2. Select the organization for which you want to import the certificate. If you do not select an organization, the certificate settings apply to all organizations and groups.
  3. Add all the certificates that you previously downloaded. You need to add them one at a time. When adding the CA, check the box to add the CA for Chromebooks.
    Note: You must install the entire certificate chain. If the root CA contains an intermediate certificate, you must install both the root and intermediate certificates. Additionally, the common name must match on the root and intermediate certs. If your Cloudpath configuration contains additional CAs, you must also import the additional CAs.

Setting up the Wi-fi Network

To create the Chromebook wi-fi network, do the following:

  1. Go to Devices > Networks > Wi-Fi.
  2. Select the organization.
  3. Click Add Wi-fi. This will invoke a page where you will enter many values. For "Platform access," check the applicable Chromebook platforms. Other important information to configure here, copied from Managed Chromebook Setup Instructions for Interactive Chromebook Enrollment, includes the following (your instructions will includes names that are specific to your own network setup):
    1. Check Automatically Connect.
    2. Set Security Type to 'WPA/WPA2-Enterprise'.
    3. Set Extensible Authentication Protocol to 'EAP-TLS'.
    4. Set Username to '@byod.company.com' or the desired value.
      Note: If using a Microsoft CA instead of the Cloudpath onboard CA, use ${CERT_SAN_UPN} in the Username field to bring the Microsoft CA User Principle Name into the identity box. For more information, refer to the following link: https://support.google.com/chrome/a/answer/2634553?hl=en#top&add&wifi&thirdparty&variables&change&managecerts&autoconnect&
    5. Set Server Certificate Authority to 'Jack Test Root CA I'.
    6. Set Client Enrollment URL to 'https://jeff245.cloudpath.net/enroll/JackTest/Production/.
    7. Set Issuer Common Name to 'Jack Test Intermediate CA I'.
      Note: If you are using a Microsoft CA instead of the Cloudpath onboard CA, use the "Issued by" value of the CA certificate.
    8. Set Issuer Organization to 'Sample Company, Inc.'.
    9. Set Issuer Organization Unit to 'IT'.
  4. Configure any additional fields.
  5. Click Save.

Adding Cloudpath Certificate Generator

To add the Cloudpath Certificate Generator, do the following:

  1. Go to Devices > Chrome > Apps & Extensions.

    Navigating to Apps & Extensions in the Google Admin Console

  2. Be sure you are in the Users and Browsers area.
  3. Open the Chrome Web Store by using the yellow plus button (+) on the bottom right of the screen.
  4. Search the Chrome Web Store for "Cloudpath Certificate Generator."
  5. Add the Cloudpath Certificate Generator.
  6. With the generator selected, from the drop-down list to the right of the generator, select "Force Install."
  7. If you are using verified access, enable the "Allow enterprise challenge" option under "Certificate Management" in the column on the right side.
  8. Click Save.

The extension is now deployed to the managed Chromebooks, along with the 'chromebook' wireless network. When the user clicks on the wireless network, the operating system looks for a certificate with the necessary issuer characteristics. If no such certificate is found, the browser opens to the client enrollment URL. Once authorized, the extension installs the certificate, and the SSID can be joined.