Supported Authentication Servers

Cloudpath supports Active Directory, LDAP and a variety of third-party authentication servers, such as Facebook, LinkedIn, or Google.

Active Directory

When using Active Directory with Cloudpath, the initial user authorization is established using AD credentials, and subsequent authentications are based on the client certificate.

Consider the following information when using Active Directory in your network.

  • You need AD domain information (plus any sub domains) and the IP address of the AD server.
  • Set up your AD groups for use with wireless BYOD access or Sponsorship Grounds (if needed).
    • Cloudpath must have layer 3 access to the AD server.
  • The AD host is an LDAP call and must be an IP routable address.
  • During authentication, the username is compared to the AD SAM attribute.
  • The FQDN of your AD server or IP address maps to the internal AD server IP address.
  • If you are using one of the hosted Cloudpath systems (onboard.cloudpath.net, onboard2.cloudpath.net, etc. ), check the Firewall Requirements page for the DNS IP address.
  • Cloudpath communicates to the AD server using TCP Port 389, LDAPS TCP/UDP 636.

LDAP or LDAPS

To use LDAP with Cloudpath, you need:

  • DNS/IP of the active directory server
  • DN of the domain
  • Username and password to bind to the LDAP server
  • Cloudpath communicates to the LDAP server using TCP Port 389.

Third-Party Authentication

When you combine third-party authentication with traditional authorization methods, the social media provides additional identity information during the onboarding process to deliver automated, self- service access to the WPA2-Enterprise wireless network. Cloudpath supports third-party integration using Facebook, LinkedIn, Google, or you can specify a custom OAuth 2.0 server.

To use third-party authentication, you need the following application information.

  • Facebook - App ID and Secret
  • LinkedIn - API Key and Secret Key
  • Google - Client ID and Client Secret.
  • Google LDAP - Client and Google LDAP client certificate zip file
Note: For details on configuring Facebook, LinkedIn, or Google applications, see the appropriate configuration guide on the Cloudpath Admin UI Support tab.

RADIUS Using PAP

Select this option to enable end-users to authenticate via RADIUS using PAP.

SAML 2.0 IdP

Cloudpath allows a Security Assertion Markup Language (SAML) Identity Provider (IdP) to be configured as an Authentication Server. With traditional authentication server types (LDAP, AD, etc) Cloudpath prompts for username/password, and the authentication server verifies the credentials. With SAML, Cloudpath delegates the IdP to prompt the user for credentials and verify the authentication.

Cloudpath Onboard Database

Select this option to enable end-users to authenticate to accounts defined within this system. This option is not meant to replace AD or LDAP system, but is useful for trial and demo accounts. You can also set specific passwords for users, as opposed to having the system set the user passwords.

Added sentence for 5.4 about setting passwords for onboard DB users.