Skip to main content

Configure eduroam Manually

phone telling users to connect to wi-fi

Users who are unable onboard with the SecureW2 configuration profile and must manually install the OSU-ROOT-CA trusted certificate. Then create an eduroam network profile using device-specific instructions below.
 

 Download Certificate

Before You Begin

  • Use an active Ohio State username and password.
  • Use another internet connection, such as cellular service or a guest network, to download the Root CA.
  • Administrative rights or the device passcode may be required to install a trusted certificate.
  • Remove an older manually created eduroam profile before rebuilding it if previous settings may conflict.

Download the Root CA

Open a browser and select Download OSU-ROOT-CA. Save the certificate file to the device so it can be installed in the platform-specific steps below.
 

Wireless Connection Settings

SettingValue
Network name (SSID)eduroam
SecurityWPA2-Enterprise or WPA3-Enterprise
EAP methodPEAP or EAP-TLS
Phase 2 authenticationMSCHAPV2 for PEAP; not used for EAP-TLS
Username / identityname.#@osu.edu
PasswordOhio State password
Server certificate validationRequired
Trusted Root CAOSU-ROOT-CA
Anonymous identityLeave blank, unless otherwise directed

 

Choose Your Authentication Method

Use PEAP with your Ohio State username and password unless a valid EAP-TLS client certificate is already installed on the device from a previous onboarding process.

MethodUse whenAuthentication
PEAPNo usable client certificate is installedname.#@osu.edu, password, and MSCHAPV2
EAP-TLSA valid client certificate and its private key are already installedInstalled client certificate; no password or Phase 2 method
 

EAP-TLS certificate check

Use EAP-TLS only when the device shows an unexpired client certificate intended for network authentication. The certificate must include access to its private key. Do not export, email, or share the certificate or private key. If no suitable certificate appears, use PEAP or contact local IT support.

 

 

Device-Specific Instructions

To continue re-onboarding choose the instructional guides that matches your device.

Windows 10 and Windows 11

Install OSU-ROOT-CA, then configure eduroam with PEAP and server validation.

 

Install OSU-ROOT-CA

  1. Locate and open the downloaded certificate file.
  2. Select Install Certificate.
  3. Choose Current User unless your support team instructs you to use the local computer store.
  4. Select Place all certificates in the following store.
  5. Select Browse, choose Trusted Root Certification Authorities, and select OK.
  6. Complete the wizard and approve the security prompt.

 

Create or Update the eduroam Profile

  1. Open Settings, select Network & Internet, and then select Wi-Fi.
  2. Open Manage known networks. If eduroam already exists, select it and choose Forget.
  3. Select Add network and enter eduroam as the network name.
  4. Choose WPA2-Enterprise or WPA3-Enterprise when available, and enable Connect automatically if desired.
  5. Configure PEAP authentication. Keep Validate server certificate enabled and select OSU-ROOT-CA as the trusted Root CA.
  6. Use name.#@osu.edu as the username or identity, enter your Ohio State password, and connect.
     

If Using an Existing EAP-TLS Certificate

  1. Confirm the client certificate appears in the Current User personal certificate store and includes its private key.
  2. In the eduroam authentication settings, select the certificate-based EAP method, commonly shown as Microsoft: Smart Card or other certificate.
  3. Keep server certificate validation enabled and select OSU-ROOT-CA as the trusted Root CA.
  4. Select the valid client certificate when Windows requests a certificate, then connect. If no suitable certificate is available, return to PEAP.

 

Validation check

Do not accept a certificate from an unknown issuer. Confirm that the presented RADIUS server certificate chains to OSU-ROOT-CA.

macOS

Install the certificate in Keychain Access, trust it, and connect to eduroam.

 

Install OSU-ROOT-CA

  1. Open the downloaded certificate file. Keychain Access should open.
  2. Add the certificate to the System keychain when available. Administrator credentials may be required.
  3. In Keychain Access, locate OSU-ROOT-CA and open the certificate details.
  4. Expand Trust and set the certificate trust setting as directed by your organization. Close the certificate window and approve the change.

 

Create or Update the eduroam Profile

  1. Open System Settings and select Wi-Fi.
  2. If an older eduroam configuration exists, remove or forget it before continuing.
  3. Select eduroam from the available networks.
  4. Enter name.#@osu.edu and your Ohio State password when prompted.
  5. Select PEAP if macOS asks for the authentication method.
  6. Review the server certificate prompt and confirm that the trust chain terminates at OSU-ROOT-CA before continuing.

If Using an Existing EAP-TLS Certificate

  1. In Keychain Access, confirm the valid client identity is available and associated with its private key.
  2. When joining eduroam, select EAP-TLS if macOS presents an authentication-method choice.
  3. Select the existing client identity certificate and confirm OSU-ROOT-CA is used to validate the RADIUS server.
  4. Connect. If the certificate is not offered or is expired, use PEAP or contact local IT support.

 

Managed devices

A device managed by your organization may restrict certificate trust changes or wireless profile editing. Contact your local IT support team if the controls are unavailable.

iPhone and iPad (iOS/iPadOS)

Install the downloaded certificate profile, enable trust, and join eduroam.

 

Install OSU-ROOT-CA

  1. Use Safari to open the OSU-ROOT-CA download link and allow the certificate profile to download.
  2. Open Settings. Select Profile Downloaded, or navigate to General > VPN & Device Management if needed.
  3. Select the downloaded profile, choose Install, and enter the device passcode.
  4. After installation, go to Settings > General > About > Certificate Trust Settings.
  5. Enable full trust for OSU-ROOT-CA and acknowledge the warning.

Join eduroam

  1. Open Settings and select Wi-Fi.
  2. If eduroam is already saved, select the information icon and choose Forget This Network.
  3. Select eduroam.
  4. Enter name.#@osu.edu and your Ohio State password.
  5. Review the RADIUS server certificate. Continue only when it is issued through the OSU-ROOT-CA trust chain.

If Using an Existing EAP-TLS Certificate

  1. Confirm the previously installed identity certificate or onboarding profile is still present under Settings > General > VPN & Device Management.
  2. Select eduroam and choose the installed identity certificate if iOS/iPadOS presents a certificate selection prompt.
  3. Confirm the RADIUS server certificate validates through OSU-ROOT-CA, then connect.
  4. If no identity certificate is offered, use PEAP or contact local IT support rather than importing or sharing a private key manually.

Security Reminder

Never install a certificate profile received through an unexpected email, text message, or pop-up. Use only the Ohio State download link in this guide.

Android

Android menu names differ by device manufacturer and operating system version.

 

Install OSU-ROOT-CA

  1. Download OSU-ROOT-CA using the link in this guide.
  2. Open Settings and search for Install a certificate, CA certificate, or Encryption & credentials.
  3. Choose the option to install a CA certificate.
  4. Select the downloaded certificate file and complete the device security prompt.

Create or Update the eduroam Profile

  1. Open Settings, select Network & internet or Connections, and open Wi-Fi.
  2. Remove or forget a previously saved eduroam profile if present.
  3. Select eduroam or choose Add network.
  4. Set EAP method to PEAP and Phase 2 authentication to MSCHAPV2.
  5. For CA certificate, select OSU-ROOT-CA. Do not select Do not validate.
  6. Enter name.#@osu.edu in Identity, leave Anonymous identity blank unless otherwise directed, and enter your Ohio State password.
  7. Save the profile and connect.

If Using an Existing EAP-TLS Certificate

  1. Confirm the valid client certificate is installed and available as a Wi-Fi or user certificate.
  2. Edit or recreate eduroam and set EAP method to TLS.
  3. Set CA certificate to OSU-ROOT-CA and select the existing client certificate in the User certificate field.
  4. Enter name.#@osu.edu in Identity if the device requires it. Leave Phase 2 authentication unset, save, and connect.

Android Certificate Field

The CA certificate field must identify OSU-ROOT-CA. Selecting Do not validate prevents the device from authenticating the RADIUS server and should not be used.

ChromeOS

Install OSU-ROOT-CA, then configure eduroam with PEAP or an existing EAP-TLS client certificate.

 

Install OSU-ROOT-CA

  1. Download OSU-ROOT-CA using the link in this guide.
  2. Open Chrome, go to Settings, select Privacy and security, select Security, and open Manage certificates. Menu labels can vary by ChromeOS version.
  3. Open the Authorities section, select Import, and choose the downloaded OSU-ROOT-CA certificate.
  4. When trust options appear, allow the certificate to identify network or website servers. Confirm OSU-ROOT-CA appears in the Authorities list.

Create or Update eduroam with PEAP

  1. Select the status area, open Settings, choose Network, and select Wi-Fi.
  2. Forget an existing eduroam profile if its settings may conflict, then select eduroam from available networks.
  3. Set Security to EAP, EAP method to PEAP, and Phase 2 authentication to MSCHAPV2.
  4. Set Server CA certificate to OSU-ROOT-CA. Do not select an option that disables certificate checking.
  5. Enter name.#@osu.edu as Identity, leave Anonymous identity blank unless otherwise directed, enter your Ohio State password, and connect.

Use an Existing EAP-TLS Certificate

  1. Open Manage certificates and confirm the valid client certificate appears under Your certificates and is bound to its private key.
  2. Open the eduroam network configuration and set Security to EAP and EAP method to EAP-TLS.
  3. Set Server CA certificate to OSU-ROOT-CA and User certificate to the existing valid client certificate.
  4. Enter name.#@osu.edu as Identity if ChromeOS requires it, then connect. If no suitable user certificate appears, use PEAP or contact local IT support

 

NOTE: Managed Chromebook

On organization-managed Chromebooks, certificate and Wi-Fi controls may be configured or restricted by policy. Contact local IT support if import or network fields are unavailable.

Verification and Troubleshooting

Use these checks before contacting support.
 

Verify the RADIUS Server Certificate

  • The certificate chain terminates at OSU-ROOT-CA.
  • The certificate is within its valid date range.
  • The prompt appears while connecting to eduroam.
  • The issuer and server identity are expected for Ohio State wireless authentication.

Certificate Not Trusted

  • Confirm OSU-ROOT-CA is installed in the correct certificate store or trust location.
  • Confirm trust is enabled where the operating system requires a separate trust setting.
  • Turn Wi-Fi off and on, or restart the device after installing the certificate.
  • Forget eduroam and recreate the profile.

Authentication Failed

  • Verify the identity is entered as name.#@osu.edu.
  • Confirm the Ohio State password is current.
  • Confirm PEAP and MSCHAPV2 are selected where those fields are displayed.
  • Confirm OSU-ROOT-CA is selected and server certificate validation is enabled.
  • For EAP-TLS, confirm a valid client certificate is selected, has not expired, and remains associated with its private key.

Certificate Warning Appears

  • Cancel the connection if the certificate cannot be validated through OSU-ROOT-CA.
  • Remove the saved eduroam profile.
  • Reinstall OSU-ROOT-CA from the Ohio State download link.
  • Recreate the wireless profile using this guide.

Need assistance?

Contact your local IT support team and provide the device type, operating system version, and a screenshot of the error. Do not include your password.