Configuring Device EAP-TLS Authentication Certificates

Vocera device supports EAP-Transport Layer Security or EAP-TLS, which provides excellent security, relying on the client and server-side certificates.

EAP-TLS is an IETF open standard and is universally supported by WLAN vendors. It provides strong security by requiring both the badge and an authentication server to prove their identities via public-key cryptography, or digital certificates. The EAP-TLS exchange is encrypted in a TLS tunnel, making it resistant to dictionary attacks.

To simplify EAP-TLS configuration, Vocera supplies client, and server-side EAP-TLS certificates called Vocera Manufacturer Certificates. To use Vocera Manufacturer Certificates, uncheck the Use Custom EAP-TLS Certificates box. You can also generate your own self-signed certificates or obtain them from a trusted Certificate Authority (CA).

If you are implementing EAP-TLS, you will need to install certificates on one of the following authentication servers:

For more information, refer to the respective vendor documentation.

The security properties you need to specify for EAP-TLS vary depending on whether you choose to use Vocera Manufacturer Certificates or custom EAP-TLS certificates. For more information, refer to the EAP Configuration Overview section of the Vocera Infrastructure Planning Guide.