Mod to remove certificate changes in Android N? - Nexus 6P Q&A, Help & Troubleshooting

Hello,
I was wondering if anyone knew of a mod (in any form/fashion) that will "revert" the certificate changes that were introduced in Android 7.0, or if this would be a possibility?
The story in the beta's was/is:
To use my Wi-Fi at my school (I literally live at school) I have to install a certificate on all devices. In Marshmallow I just enter my credentials when connecting to the Wi-Fi, and it connects, however there is no internet connection yet, I then have to open the browser and visit cert.localnetwork.zone, and install the certificate which then allows me access to the internet (well, 'restricted' access, hence the purpose of the certificate).
However, in N, there are some extra steps, when I [connect to the Wi-Fi I have to select between use system certificates and do not validate, which I then select "do not validate", as I don't have any certificates installed on the device to use, and I don't know the domain to enter for the other, and it kicks up an error if I enter cert.localnetwork.zone (the only thing I could think to use). Then when I go to Chrome just like any other time I go to cert.localnetwork.zone, and download and install the certificate like any other ROM I would do it on. It installs and grants me access to the internet, however the access is 'different'.
I can't use the Google App, which means that Google Now doesn't work at all, neither does the search bar on the GNL, going to Chrome I can't search something in the URL bar, instead I have to go to bing.com, and then search it from there (google.com returns an error). I open Sync for Reddit (Pro), and it will not load returning that I have no internet connection, however upon using the official Reddit app, everything works fine. Using the Bing app results in the same error as the Google App (no internet connection), however when using the bing website as mentioned before it works fine. Other services like Google Plus do not work either.
But I am still able to access the Play Store, Gmail, Inbox, Twitter, Tumblr and other services just as I would before, but it seems that anything using https, does not work due to an added security measure. However, when switching to another Wi-Fi network, or using my data, everything returns and works as per usual (which is quite annoying, when a heap of Google Now, Reddit etc notifications come streaming in). Every version of the N preview has been like this, however any version of 6.x has no problem. I haven't come across this error on any other devices (OnePlus One, Nexus 5, iPhone 6, Macbook Pro, Dell XPS 13, Chromebook Pixel, Nexus 7). I've basically narrowed it down to the connection not being private, as it says when I press "do not validate", however I don't know of any other way to connect to the Wi-Fi..
However, in the official 7.0 release it's even worse, now I connect to the Wi-Fi, and I can ONLY access the Play Store (which works without the certificate being installed anyway). I contacted our IT department, and they said that this is not something that they can change since they are required by the ADoE to monitor internet activity.
So I was wondering if there was some either mod/rom or ANYTHING that would allow me to revert the certificate changes in 7.0, or a root app or whatever that allowed connections on an "insecure" Wi-Fi network.

Related

Getting internet programs to connect without IE

My Schools network uses clean access agent, which checks to make sure your windows device has the correct authentication. It will not let me go on ie, as it sees that I do not have the correct Virus protection etc. However it lets you use Opera, as it just lets it bypass the checks because none are in place for it.
I can use Opera or Skyfire, that isn't a prob. But when I try to use a program that connects to the Internet such AIM or QuickGPS, It won't work. Im assuming that the program is using IE to access the data. Although I have no idea how a program connects to the Internet (Does it use a browser?) Anyway, is there a way I can change the settings to get the program to use Opera?
Thanks,
I'm not sure that it will work, but you could try changing your default browser.
There are many threads in the forum with this information, Here's one, do a search for others.
hey, if you talk to your university's computer support team, they may tweak their internet settings so mobile browsing can work. i go to western connectisut state university, and i e-mailed the computer center with this problem (i dormed on campus and the ResiNET they used blocked me as well b/c i didnt install clean access agent. the university's network read my device as if it was a desktop since they blocked me saying i needed to install that ****ty software). once i did that, they e-mailed me back saying they updated their systems so i was able to use the web-based login, and then i began surfing the net. once u logged in, you should be able to update the GPS & use AIM with no real problems.
i hope this helps! there isn't a real way to bypass the system. believe me, i tried searching for ways to bypass the system. changing your default browser won't remedy it b/c the network only reads IP addresses and the fact information (doesn't matter what it is) is being pass through its network, it will block it without proper ID keys from the web-based log in. i even tried searching for a mobile version of cisco clean access agent but there isnt such software. like i said, talk to your university computing center and they can help you. it is really up to them to be able to change the settings around.

Vibrant Wifi problem (Clean Access)

I have a stock Samsung Vibrant. It connects to my home wifi network just fine and is very fast.
At my school we have to register the mac address' of devices we have on their Clean Access servers. I have registered many devices that work fine.
I registered the mac address of my Vibrant, and it can connect to the wifi, but it will not load a web page. Does anyone have any idea of what is wrong.
I also registered my roommates Vibrant. His does not work either.
I work at the Schools Tech Support so I have access to register and edit my phone on their Clean Access servers.
Does anyone have any solutions?
are you using WPA/WPAv2 or WEP + RADIUS authentication? Does your vibrant obtain an IP address successfully? Can you ping the default router?
The wifi that works at my apartment is WPA2.
The wifi at school is an open network. I can fully connect to their wifi.
Status Connected
Speed 48Mbps
Signal Strength Good
Security Open
IP address (a real IP address)
Im going out on a limb here. I am going to say its the Clean access and your "open network". I assume on your schools computer you use your student ID and some password. Your phone would need the same thing if that is the case. I know at my school, iphones are the only phones that can access our clean access. If its not the case then i am sorry.
my school runs clean access and it works fine. but they have two networks a guest and a login. i use the guest cause i don't want to waste the time to login. but i can try it on monday. typically with linux (i.e. android) you have a web portal and have to agree to some antivirus bs by clicking a button and that's it (and login for the non guest network). one thing i have noticed, though, is that typically i have to turn wifi on, connect to the network, try to load a page, it doesn't work, then i turn wifi off then immediately back on and try to load a page and it takes me to the login/terms portal page.
GTASouthPark said:
The wifi that works at my apartment is WPA2.
The wifi at school is an open network. I can fully connect to their wifi.
Status Connected
Speed 48Mbps
Signal Strength Good
Security Open
IP address 140.209.21.68
Click to expand...
Click to collapse
You should remove the IP from post. Anyways, it seems like the handshake is good. Note down the address of redirected terms and conditions page you get when trying to go online from a laptop. Then enter the same address in vibrant's browser once you are connected through Wifi ( or set it as homepage) and see if that lets it through.
Probably an issue with Android's lack of native NTLM support. AFAIK this is still unresolved. Have you tried using Fennec rather than the stock browser? I've heard you can authenticate properly using it.
Siks said:
Probably an issue with Android's lack of native NTLM support. AFAIK this is still unresolved. Have you tried using Fennec rather than the stock browser? I've heard you can authenticate properly using it.
Click to expand...
Click to collapse
interesting. i use dolphin hd and it works for the clean access web authentication page.
Could be, if your school does not have a guest account login for devices, that you are getting on the segregated network because CA cannot verify the "cleanliness" of your device. When I setup CA it verified patch levels and such on the non-guest network, so unless CA comes out with a Android client/access list, it may not work.
watcher64 said:
Could be, if your school does not have a guest account login for devices, that you are getting on the segregated network because CA cannot verify the "cleanliness" of your device. When I setup CA it verified patch levels and such on the non-guest network, so unless CA comes out with a Android client/access list, it may not work.
Click to expand...
Click to collapse
except then it wouldn't allow osx or linux. clean access requires an app for windows to verify service pack and av and whatever, but for linux and osx it doesn't. it wouldn't be able to (at least for linux).
funeralthirst said:
except then it wouldn't allow osx or linux. clean access requires an app for windows to verify service pack and av and whatever, but for linux and osx it doesn't. it wouldn't be able to (at least for linux).
Click to expand...
Click to collapse
That is correct but it can ID the operating system and has exceptions for those flavors ...
Hey it's me again.
I don't think it's an android thing because I had my G1 on the servers.
Normally what happens if you aren't registered on Clean Access is, if you open a web browser, you will be automatically redirected to an authentication page where you put in your school ID and password. This would work fine and allow me to get on the wifi, but it never came up on the web browser, it just tries to load the page for awhile and goes to a 'Page cannot be displayed' page.
Also I have tried using different browsers, including Dolphin HD.
If I can just get to the authentication page even it will be fine, I could work with that.
Also the school does have a guest login, but you have to get to the authentication page, and I wouldnt want guest access since it limits time, bandwidth, and features.
That is exactly what I said my last reply...Try putting https infront of your authentication URL, and make sure the java-script etc. is on in your browser...Try clearing cache and hit refresh as well. Also, see what happens if you set that URL as homepage...
GTASouthPark said:
Hey it's me again.
I don't think it's an android thing because I had my G1 on the servers.
Normally what happens if you aren't registered on Clean Access is, if you open a web browser, you will be automatically redirected to an authentication page where you put in your school ID and password. This would work fine and allow me to get on the wifi, but it never came up on the web browser, it just tries to load the page for awhile and goes to a 'Page cannot be displayed' page.
Also I have tried using different browsers, including Dolphin HD.
If I can just get to the authentication page even it will be fine, I could work with that.
Also the school does have a guest login, but you have to get to the authentication page, and I wouldnt want guest access since it limits time, bandwidth, and features.
Click to expand...
Click to collapse
did you try turning on wifi, wait for it to connect, try to load a page (any page because it will redirect you), wait for it to time out, pull down the notification bar, turn wifi off, turn it back on and then reload the page? i know it sounds dumb, but this is the only way i've got it to work at my school and it works every time...
watcher64 said:
That is correct but it can ID the operating system and has exceptions for those flavors ...
Click to expand...
Click to collapse
to what flavors? i'm guessing android will show as linux since it's based off a linux kernel. more than likely it checks for windows, and if false goes to the default linux/osx page because to clean access those aren't threat os's.
VICosPhi said:
That is exactly what I said my last reply...Try putting https infront of your authentication URL, and make sure the java-script etc. is on in your browser...Try clearing cache and hit refresh as well. Also, see what happens if you set that URL as homepage...
Click to expand...
Click to collapse
they don't have the authentication URL on their homepage so I don't know what it is, it should automatically redirect me to it.
Also when I connect to wifi, try to load a page, let it time out, turn off wifi, turn it back on and connect again, and then refresh the page.. nothing happens it times out again.
Ok so I did find out the authentication page URL. Typed it into my phone. I had high hopes when a page saying "You are being redirected to the network authentication page. If you are not redirected automatically, then please click HERE".
Anyway it did redirect me, to a "Web page not available"... etc.
In the default browser it gave me the error... "Data connectivity problem. A secure connection could not be established". umm wtf?
Can you communicate with other protocols/ports? I used to be able to exploit a bug with our school's CCA servers where I could just connect unauthenticated and use SSH. (Maybe it was a feature?)
I can't use any other web protocols.
Bump. Okay. I've figured out how to do this . '
it's a t mobile vibrant either kernel or rom problem. My phone connected the very first time I tried to use it at an argosy site, then never ever ever again.
so. I used wifi manager to find out what the ip, gateway, subnet mask, and dns 1 and 2 were. I went to settings, wifi, options key to go to advanced options, from there selected static ip and entered all the info I gathered
bam! ! Connected every time.
Oh and btw, the reason I say its a tmobile vibrant rom or kernel problem is that on fusion, Eugene's and bionix final, I was able to connect right away, every time . And on my f friends att fascinate and verizon captivate, they never had to enter the static ip like I did. They connected right away every time . Yet everyone I know that had s vibrant kept having the same proble. m i did .
Tmobile. What a piece of ****. Anyway I figured nobody had this figured out so I'd jump in.
Hope this helps out some people. GL

[Q] How do I connect LG Vortex (Android 2.2) to my company Wifi and use apps over it?

I have recently purchased an LG Vortex that comes with the Android 2.2 operating system installed. I have looked into rooting my phone with z4root and have successfully temporarily rooted my phone. I would rather keep my phone unrooted, but if it is absolutely necessary I will root it permanently with z4root.
My question is this: How can I connect to my company wifi and use apps that require wifi?
I can successfully connect to my corporate wifi through the 802.1x EAP protocol. The problem comes when trying to access any of the apps that require internet (I am forcing Verizon's data plan not to be used--using wifi only due to 150MB limit on my data to save $$ per month). None of my apps seem to work--internet browser, Market, Gmail, Google Calendar, etc...
On my company pc I know that within internet explorer the box is checked that says "Use automatic configuration script" and gives an "Address" that is in the format of "..../proxy.pac" It looks like my work uses a proxy for things to connect to the internet. I have no such place to put this information in my LG Vortex. I downloaded an app that seemed promising called "Proxy Settings" which will allow me to enter in the following Hostname and Port. When I tried to enter the "..../proxy.pac" as the hostname it gave me an error stating "The hostname you typed is not valid."
Is there an app or something that will allow me to use my apps when connecting to my corporate wifi? Is it a proxy setting thing or a VPN thing? I am not sure. I am open to any and every idea so that I can use my phone's online features while connected to my company's wifi.
FYI - I have friends that have iPod touches and they are able to connect to the internet with some apps internet browsing and downloading apps, but they have a similar issue of not being able to use all of their apps as well. I believe they were able to put the "..../proxy.pac" address in their devices somewhere.
Thanks!
abarkena, check out Autoproxy on the market. You can add a new proxy, put in the address to the proxy.pac file, and it will connect to the correct proxy every time. It works for market, maps, gmail, the works.
That's also good if you're on a network where they keep changing the proxy (like the place I work).

Fire TV & Stick on secure (hotel, etc.) networks...

I searched briefly & had no luck, but this was a pretty simple find, so I am sure many have already worked this out...
At any rate, we all know that Amazon says "coming soon" on using networks that require a web page sign in for internet access, like you find in many hotels & other establishments that require you consent or a password to be entered via a network sign in page...
As a frequent traveler, one of the reasons I have both the Fire TV & the Stick, was to be able to take my show with me. Well, I was not happy to find this as the case on an updated unrootable device while on the road. I didn't have ADB to push any apps on my device, but wanted to buy the latest Hobbit movie, so I found a work around that was simple & required no laptop, no usb, just an initial network you can access, like from home or work, or any open network.
At any rate, all you need to do is install the HTML5 App Tester apk, found here: http://www.amazon.com/Amazon-Digital-Services-Inc-Tester/dp/B00DZ3I1W8
Once installed (which requires an open or secure access point without a required web sign in (I used tethering from my mobile device), you then go to the web page launch & set up anything as an address, since those hotel access points redirect you anyway. I set up www.google.com.
The you just select the hotel or other log in/accept terms/enter password on web page as your network in settings & once it connects, go to settings, Applications, Manage All Application, scroll to the Web App Tester & launch it from the menu & then launch the web page from the Web App Tester application. It will then redirect you to the sign in page on whatever network you are connected to & voila, you are now connected to the Internet & can steam your heart out, unless they have firewall restrictions of course... So far, it has worked on every hotel network I have tried. All Hilton & Sheraton families of hotels, DoubleTree & numerous botique or one off hotels B&B & other chains.
You're in luck. Amazon is pushing an update that lets you the Fire TV connect to public networks with login pages such as hotels or dorm rooms: Amazon Media Room: Press Releases
Beforei the update couldn't you simply do it by sideloading a web browser so that fire can open links, then sign-in in a web browser.. of course you would need a mouse and keboard,but like the other guy mentioned a nice OTA is incoming!
patt2k said:
Beforei the update couldn't you simply do it by sideloading a web browser so that fire can open links, then sign-in in a web browser.. of course you would need a mouse and keboard,but like the other guy mentioned a nice OTA is incoming!
Click to expand...
Click to collapse
Another easy thing to do is to solve the issue externally. Check out getting a HooToo Tripmate.. It will let you start up an authenticated wireless hotspot and you can connect to it with anything you want - roku, firetv, tablet etc. It works for networks that require web page login, or WIFI password authentication. It has other advantages as well you might like - usb battery pack etc.. Depending on the model, they start at $20.. I never take a trip without mine.. It has become a priceless addition to my equipment..
Just my $.02

Can't add google account SM-N9005, date and time correct

I just booted up my old note 3 for use as a drone controller, but for some weird reason I am unable to get into the play store because every time I try to add a google account it gives me the message 'Cannot establish reliable connection to server' despite my internet connection working perfectly fine (can access play store on chrome and android browser)
At first I thought this might be due to a date/time error but even after manually setting the date and time (as well as automatic settings) the error persists. The weather app, S assistant, Youtube and web browsing works fine, however several applications like Flipboard, ChatOn, DJI Go 4 and any type of google service which requires a account are all unable to connect to their servers. I've tried using a different WAP, verifying client access via the web and factory resetting the phone, but nothing seems to fix it.
If anyone knows how I can fix this it would be greatly appreciated.

Categories

Resources