The University transitioned from certificates issued by the CREN root certificate authority to certificates issued by the USHER root certificate authority on Tuesday, July 31, 2007. Existing Mac wireless users (not users setting up for the first time) will need to follow these instructions after they obtain their new USHER user certificate and before Monday, August 13, 2007 in order to have uninterupted connectivity to UVa encrypted wireless networks.
Instructions
Manually selecting the new USHER issued client certificate
- From the AirPort menu, select Open Internet Connect....

- Click the 802.1x icon.
- From the Configuration dropdown select Edit Configurations....

- Make sure their is only one Cavalier Wireless Network Profile (if there is more than one, delete the extras by selecting them in the list and clicking the – (minus) button below the list).
- Click the Configure button.
- From the Select your TLS certificate dropdown, select the highest number certificate.

- Click the OK button to close the Select Certificate window.
- Click the OK button to save your configuration change.
- Quit the Internet Connect utility.
Install the Root Certificate
- Download the Wireless Configuration Bundle to your desktop or your designated download folder.
- If it doesn't mount automatically, locate and double-click on the
wirelessbundle.dmgfile to mount the Wireless Bundle disk image. - From the Wireless Bundle disk image, locate and double-click the
usher-root.cerfile (ignore the other file). The Add Certificates window will appear to ask if you would like to add the certificate to the keychain.
- From the Keychain drop-down, select X509Anchors.
- Click the OK button.
- To complete the process, you will be asked to enter your password for your computer.
- Click the OK button to close the Add Certificates window.
Trusting the USHER CA Root Certificate
- In the Keychain Access utility left column, click Certificates, then locate the USHER CA1 v1 certificate in the list to the right.

- Double click the USHER CA1 v1 certificate, a USHER CA1 v1 window will appear.
- Click the Details triangle to collapse its section.
- Click the Trust Settings triangle to expand its section.
- From the Extensible Authentication (EAP) drop-down, select Always Trust.

- Close the USHER CA1 v1 window.
- Quit the Keychain Access utility.
