Add ChromeOS Wi-Fi enrollment via ACME Device Attestation - #546
Conversation
d79ea11 to
0b3c143
Compare
|
|
||
| <Alert severity="info" mb={4}> | ||
| <div> | ||
| Skip Step 1 (credential) and the Wi-Fi resource created at the top of Step 3 for ChromeOS. Neither applies here: the client certificate comes from Certificate Manager directly, and the Wi-Fi network profile is delivered by Google Admin rather than by Smallstep. |
There was a problem hiding this comment.
Eventually we'll want these resources to still be created, so that the ChromeOS agent can get a full configuration, with more use cases automatically handled. We'll have to ensure that we have docs on root distribution for all use cases configured for ChromeOS.
There was a problem hiding this comment.
Oh, interesting. I understand why a credential might be valuable for this, but is the extension also going to be capable of taking over Wi-Fi or VPN config settings?
- Trim the redundant "not through MDM/Smallstep resources" clause. - Trust store only needs the authority's root — ChromeOS's EAP-TLS handshake already includes the client intermediate. - "No RADIUS traffic" isn't always a certificate-selection failure; it can also mean no device identity certificate was issued at all. Per Herman's review comments on smallstep#546.
0b3c143 to
3c51717
Compare
| 5. Click **Continue** | ||
| 6. Select **OpenID Connect (OIDC)** as the provider | ||
| 7. Set a name, e.g. "Smallstep Google Workspace Sync" | ||
| 8. Set the issuer URL to **https://container.googleapis.com/v1/projects/prod-us-central1-e5bd/locations/us-central1/clusters/primary** |
There was a problem hiding this comment.
Is there any way to get a cleaner issuer URL?
(I think the answer is no, because it's a Google token and a Google URL...)
There was a problem hiding this comment.
@hslatman Just a half-formed thought here: would it be worth the effort or even valuable at all to have a separate GCP project that acts as issuer for this? Maybe something branded, and that can be differentiated from the prod tenant.
- Trim the redundant "not through MDM/Smallstep resources" clause. - Trust store only needs the authority's root — ChromeOS's EAP-TLS handshake already includes the client intermediate. - "No RADIUS traffic" isn't always a certificate-selection failure; it can also mean no device identity certificate was issued at all. Per Herman's review comments on smallstep#546.
Homelab-specific advice from testing this setup — not realistic guidance for enterprise customers, who won't be running their own FreeRADIUS server. Also addresses the ambiguity Carl flagged about whether this implied running freeradius on the Chromebook itself. Per Carl's review comment on smallstep#546.
1493482 to
e10033c
Compare
|
All inline feedback addressed, and Carl's directly-pushed commit ("Some suggested updates") is merged in as-is:
Two threads are intentionally left open since they're follow-up architecture questions for Herman, not doc fixes: the WIF issuer URL cleanliness question and whether the extension will eventually take over Wi-Fi/VPN config. Still in Draft — I'll mark it ready once #545 merges, since right now its diff includes #545's changes too. |
The merge-base changed after approval.
Summary
Blocked on #545 — this branch is stacked on top of it, so the diff below currently includes #545's changes too. Once #545 merges, this diff will automatically collapse down to just this PR's own changes and it'll be ready for review. Opening now as a draft so it's visible and trackable rather than sitting only in my fork.
Test plan
valerun against changed files (noise-filtered against house style — no unaddressed findings)markdown-link-checkrun against changed files — all internal/external links resolve once Add ChromeOS device identity certificates tutorial #545 is merged🤖 Generated with Claude Code