Users who are unable onboard with the SecureW2 configuration profile and must manually install the OSU-ROOT-CA trusted certificate. Then create an eduroam network profile using device-specific instructions below.
Before You Begin
- Use an active Ohio State username and password.
- Use another internet connection, such as cellular service or a guest network, to download the Root CA.
- Administrative rights or the device passcode may be required to install a trusted certificate.
- Remove an older manually created eduroam profile before rebuilding it if previous settings may conflict.
Download the Root CA
Open a browser and select Download OSU-ROOT-CA. Save the certificate file to the device so it can be installed in the platform-specific steps below.
Wireless Connection Settings
| Setting | Value |
|---|---|
| Network name (SSID) | eduroam |
| Security | WPA2-Enterprise or WPA3-Enterprise |
| EAP method | PEAP or EAP-TLS |
| Phase 2 authentication | MSCHAPV2 for PEAP; not used for EAP-TLS |
| Username / identity | name.#@osu.edu |
| Password | Ohio State password |
| Server certificate validation | Required |
| Trusted Root CA | OSU-ROOT-CA |
| Anonymous identity | Leave blank, unless otherwise directed |
Choose Your Authentication Method
Use PEAP with your Ohio State username and password unless a valid EAP-TLS client certificate is already installed on the device from a previous onboarding process.
| Method | Use when | Authentication |
|---|---|---|
| PEAP | No usable client certificate is installed | name.#@osu.edu, password, and MSCHAPV2 |
| EAP-TLS | A valid client certificate and its private key are already installed | Installed client certificate; no password or Phase 2 method |
EAP-TLS certificate check Use EAP-TLS only when the device shows an unexpired client certificate intended for network authentication. The certificate must include access to its private key. Do not export, email, or share the certificate or private key. If no suitable certificate appears, use PEAP or contact local IT support. | ||
Device-Specific Instructions
To continue re-onboarding choose the instructional guides that matches your device.
Windows 10 and Windows 11
Install OSU-ROOT-CA, then configure eduroam with PEAP and server validation.
Install OSU-ROOT-CA
- Locate and open the downloaded certificate file.
- Select Install Certificate.
- Choose Current User unless your support team instructs you to use the local computer store.
- Select Place all certificates in the following store.
- Select Browse, choose Trusted Root Certification Authorities, and select OK.
- Complete the wizard and approve the security prompt.
Create or Update the eduroam Profile
- Open Settings, select Network & Internet, and then select Wi-Fi.
- Open Manage known networks. If eduroam already exists, select it and choose Forget.
- Select Add network and enter eduroam as the network name.
- Choose WPA2-Enterprise or WPA3-Enterprise when available, and enable Connect automatically if desired.
- Configure PEAP authentication. Keep Validate server certificate enabled and select OSU-ROOT-CA as the trusted Root CA.
- Use name.#@osu.edu as the username or identity, enter your Ohio State password, and connect.
If Using an Existing EAP-TLS Certificate
- Confirm the client certificate appears in the Current User personal certificate store and includes its private key.
- In the eduroam authentication settings, select the certificate-based EAP method, commonly shown as Microsoft: Smart Card or other certificate.
- Keep server certificate validation enabled and select OSU-ROOT-CA as the trusted Root CA.
- Select the valid client certificate when Windows requests a certificate, then connect. If no suitable certificate is available, return to PEAP.
Validation check
Do not accept a certificate from an unknown issuer. Confirm that the presented RADIUS server certificate chains to OSU-ROOT-CA.
macOS
Install the certificate in Keychain Access, trust it, and connect to eduroam.
Install OSU-ROOT-CA
- Open the downloaded certificate file. Keychain Access should open.
- Add the certificate to the System keychain when available. Administrator credentials may be required.
- In Keychain Access, locate OSU-ROOT-CA and open the certificate details.
- Expand Trust and set the certificate trust setting as directed by your organization. Close the certificate window and approve the change.
Create or Update the eduroam Profile
- Open System Settings and select Wi-Fi.
- If an older eduroam configuration exists, remove or forget it before continuing.
- Select eduroam from the available networks.
- Enter name.#@osu.edu and your Ohio State password when prompted.
- Select PEAP if macOS asks for the authentication method.
- Review the server certificate prompt and confirm that the trust chain terminates at OSU-ROOT-CA before continuing.
If Using an Existing EAP-TLS Certificate
- In Keychain Access, confirm the valid client identity is available and associated with its private key.
- When joining eduroam, select EAP-TLS if macOS presents an authentication-method choice.
- Select the existing client identity certificate and confirm OSU-ROOT-CA is used to validate the RADIUS server.
- Connect. If the certificate is not offered or is expired, use PEAP or contact local IT support.
Managed devices
A device managed by your organization may restrict certificate trust changes or wireless profile editing. Contact your local IT support team if the controls are unavailable.
iPhone and iPad (iOS/iPadOS)
Install the downloaded certificate profile, enable trust, and join eduroam.
Install OSU-ROOT-CA
- Use Safari to open the OSU-ROOT-CA download link and allow the certificate profile to download.
- Open Settings. Select Profile Downloaded, or navigate to General > VPN & Device Management if needed.
- Select the downloaded profile, choose Install, and enter the device passcode.
- After installation, go to Settings > General > About > Certificate Trust Settings.
- Enable full trust for OSU-ROOT-CA and acknowledge the warning.
Join eduroam
- Open Settings and select Wi-Fi.
- If eduroam is already saved, select the information icon and choose Forget This Network.
- Select eduroam.
- Enter name.#@osu.edu and your Ohio State password.
- Review the RADIUS server certificate. Continue only when it is issued through the OSU-ROOT-CA trust chain.
If Using an Existing EAP-TLS Certificate
- Confirm the previously installed identity certificate or onboarding profile is still present under Settings > General > VPN & Device Management.
- Select eduroam and choose the installed identity certificate if iOS/iPadOS presents a certificate selection prompt.
- Confirm the RADIUS server certificate validates through OSU-ROOT-CA, then connect.
- If no identity certificate is offered, use PEAP or contact local IT support rather than importing or sharing a private key manually.
Security Reminder
Never install a certificate profile received through an unexpected email, text message, or pop-up. Use only the Ohio State download link in this guide.
Android
Android menu names differ by device manufacturer and operating system version.
Install OSU-ROOT-CA
- Download OSU-ROOT-CA using the link in this guide.
- Open Settings and search for Install a certificate, CA certificate, or Encryption & credentials.
- Choose the option to install a CA certificate.
- Select the downloaded certificate file and complete the device security prompt.
Create or Update the eduroam Profile
- Open Settings, select Network & internet or Connections, and open Wi-Fi.
- Remove or forget a previously saved eduroam profile if present.
- Select eduroam or choose Add network.
- Set EAP method to PEAP and Phase 2 authentication to MSCHAPV2.
- For CA certificate, select OSU-ROOT-CA. Do not select Do not validate.
- Enter name.#@osu.edu in Identity, leave Anonymous identity blank unless otherwise directed, and enter your Ohio State password.
- Save the profile and connect.
If Using an Existing EAP-TLS Certificate
- Confirm the valid client certificate is installed and available as a Wi-Fi or user certificate.
- Edit or recreate eduroam and set EAP method to TLS.
- Set CA certificate to OSU-ROOT-CA and select the existing client certificate in the User certificate field.
- Enter name.#@osu.edu in Identity if the device requires it. Leave Phase 2 authentication unset, save, and connect.
Android Certificate Field
The CA certificate field must identify OSU-ROOT-CA. Selecting Do not validate prevents the device from authenticating the RADIUS server and should not be used.
ChromeOS
Install OSU-ROOT-CA, then configure eduroam with PEAP or an existing EAP-TLS client certificate.
Install OSU-ROOT-CA
- Download OSU-ROOT-CA using the link in this guide.
- Open Chrome, go to Settings, select Privacy and security, select Security, and open Manage certificates. Menu labels can vary by ChromeOS version.
- Open the Authorities section, select Import, and choose the downloaded OSU-ROOT-CA certificate.
- When trust options appear, allow the certificate to identify network or website servers. Confirm OSU-ROOT-CA appears in the Authorities list.
Create or Update eduroam with PEAP
- Select the status area, open Settings, choose Network, and select Wi-Fi.
- Forget an existing eduroam profile if its settings may conflict, then select eduroam from available networks.
- Set Security to EAP, EAP method to PEAP, and Phase 2 authentication to MSCHAPV2.
- Set Server CA certificate to OSU-ROOT-CA. Do not select an option that disables certificate checking.
- Enter name.#@osu.edu as Identity, leave Anonymous identity blank unless otherwise directed, enter your Ohio State password, and connect.
Use an Existing EAP-TLS Certificate
- Open Manage certificates and confirm the valid client certificate appears under Your certificates and is bound to its private key.
- Open the eduroam network configuration and set Security to EAP and EAP method to EAP-TLS.
- Set Server CA certificate to OSU-ROOT-CA and User certificate to the existing valid client certificate.
- Enter name.#@osu.edu as Identity if ChromeOS requires it, then connect. If no suitable user certificate appears, use PEAP or contact local IT support
NOTE: Managed Chromebook
On organization-managed Chromebooks, certificate and Wi-Fi controls may be configured or restricted by policy. Contact local IT support if import or network fields are unavailable.
Verification and Troubleshooting
Use these checks before contacting support.
Verify the RADIUS Server Certificate
- The certificate chain terminates at OSU-ROOT-CA.
- The certificate is within its valid date range.
- The prompt appears while connecting to eduroam.
- The issuer and server identity are expected for Ohio State wireless authentication.
Certificate Not Trusted
- Confirm OSU-ROOT-CA is installed in the correct certificate store or trust location.
- Confirm trust is enabled where the operating system requires a separate trust setting.
- Turn Wi-Fi off and on, or restart the device after installing the certificate.
- Forget eduroam and recreate the profile.
Authentication Failed
- Verify the identity is entered as name.#@osu.edu.
- Confirm the Ohio State password is current.
- Confirm PEAP and MSCHAPV2 are selected where those fields are displayed.
- Confirm OSU-ROOT-CA is selected and server certificate validation is enabled.
- For EAP-TLS, confirm a valid client certificate is selected, has not expired, and remains associated with its private key.
Certificate Warning Appears
- Cancel the connection if the certificate cannot be validated through OSU-ROOT-CA.
- Remove the saved eduroam profile.
- Reinstall OSU-ROOT-CA from the Ohio State download link.
- Recreate the wireless profile using this guide.
Need assistance?
Contact your local IT support team and provide the device type, operating system version, and a screenshot of the error. Do not include your password.