Supported Authentication Servers
Cloudpath supports Active Directory, LDAP and a variety of third-party authentication servers, such as Facebook, LinkedIn, or Google.
Active Directory
When using Active Directory with Cloudpath, the initial user authorization is established using AD credentials, and subsequent authentications are based on the client certificate.
Consider the following information when using Active Directory in your network.
- You need AD domain information (plus any sub domains) and the IP address of the AD server.
- Set up your AD groups for use with wireless BYOD access or Sponsorship Grounds (if needed).
- The AD host is an LDAP call and must be an IP routable address.
- During authentication, the username is compared to the AD SAM attribute.
- The FQDN of your AD server or IP address maps to the internal AD server IP address.
- If you are using one of the hosted Cloudpath systems (onboard.cloudpath.net, onboard2.cloudpath.net, etc. ), check the Firewall Requirements page for the DNS IP address.
- Cloudpath communicates to the AD server using TCP Port 389, LDAPS TCP/UDP 636.
LDAP or LDAPS
To use LDAP with Cloudpath, you need:
Third-Party Authentication
When you combine third-party authentication with traditional authorization methods, the social media provides additional identity information during the onboarding process to deliver automated, self- service access to the WPA2-Enterprise wireless network. Cloudpath supports third-party integration using Facebook, LinkedIn, Google, or you can specify a custom OAuth 2.0 server.
To use third-party authentication, you need the following application information.
- Facebook - App ID and Secret
- LinkedIn - API Key and Secret Key
- Google - Client ID and Client Secret.
- Google LDAP - Client and Google LDAP client certificate zip file
RADIUS Using PAP
Select this option to enable end-users to authenticate via RADIUS using PAP.
SAML 2.0 IdP
Cloudpath allows a Security Assertion Markup Language (SAML) Identity Provider (IdP) to be configured as an Authentication Server. With traditional authentication server types (LDAP, AD, etc) Cloudpath prompts for username/password, and the authentication server verifies the credentials. With SAML, Cloudpath delegates the IdP to prompt the user for credentials and verify the authentication.
Cloudpath Onboard Database
Select this option to enable end-users to authenticate to accounts defined within this system. This option is not meant to replace AD or LDAP system, but is useful for trial and demo accounts. You can also set specific passwords for users, as opposed to having the system set the user passwords.