Installing the SecureW2 Certificate


Overview


Unmanaged devices that are unable to install or run Qualys, Trellix, or Intune will need to file for an exception in order to connect to the UCSD VPN secure-connect tunnel groups. If an exception request is approved, then a device certificate will be issued. The following article outlines how to download and install this device certificate for MacOS, Windows, and Linux devices.

Critical Concepts


Steps to Take


MacOS

  1. Navigate to the link provided to you in your approved exception request ticket.
  2. Ensure that the “Select your device” option at the bottom of the page says “macOS”. If not, click on the dropdown menu and choose macOS.

    Screenshot of the landing page for downloading the Secure W2 certificate on Mac devices with approved exceptions

  3. Click on Certificate Download. An installer will automatically download under the name “UCSD_BYOD_Enrollment.dmg”. If you get a pop-up window to save the file, click Save.
  4. Click on the installer to open it. 
  5. The following pop-up window will appear. Double-click on the icon to run the installer.

    Screenshot of Secure W2 installer icon with a the label "UCSD_BYOD_Enrollment" underneath

  6. You may get the following message. Click Don’t Allow.

    Screenshot of permissions request to allow "UCSD_BYOD_Enrollment" to find devices on local networks

  7. The following warning will appear. Click Open to proceed with the installation.

    Screenshot of pop-up warning for downloading the Secure W2 application from the interent

  8. Another pop-up will appear asking to enter the device password in order to make changes to the Certificate Trust Settings. Enter your Administrative (system) username and password, then click Update Settings.
  9. Next, click on the following window to navigate to it and click Next.

    Screenshot of pop-up window with instructions on installing the Secure W2 profile on the device

  10. You will be redirected to a Single Sign-On page. Enter your active directory (AD) credentials and click Login.
  11. You will then receive a Duo prompt. Approve the prompt to proceed.
  12. Navigate back to the pop-up window from step 9. Click Next.
  13. Another pop-up window will appear. Click OK.
  14. You will then be redirected to your System Settings. Double-click on the “University of California San Diego UCSD-PROTECTED” profile.

    Screenshot of University of California San Diego UCSD profile in the device's Device Management settings

  15. You will then see the following screen. Click Install.

    Screenshot of windows asking for confirmation to install the University of California San Diego UCSD profile

  16. Click Install again. If prompted, enter your Administrative (system) username and password.
  17. Back on the pop-up window from step 9, click Done.
  18. You will be redirected to the “Configure VPN Client on your Computer, Tablet, or Phone” KBA. If you have already installed the Cisco Secure Client VPN, you can close out the window.
  19. Open the VPN. In the window that appears, type in "vpn-exception.ucsd.edu", then click Connect.
  20. Enter your UCSD credentials and click OK.
  21. You may get the following prompt. Input your Administrative (system) username and password and click Always Allow.

    Screenshot of Cisco Secure Client request to access the "SecureW2 JoinNow Any Access" key in the keychain

Windows

  1. Navigate to the link provided to you in your approved exception request ticket.
  2. Ensure that the “Select your device” option at the bottom of the page says “Windows 10 & Above”. If not, click on the dropdown menu and choose Windows 10 & Above.

    Screenshot of the landing page for downloading the Secure W2 certificate on Windows devices with approved exceptions

  3. Click on Certificate Download. An installer will automatically download under the name “UCSD_BYOD_Enrollment.exe”. If you get a pop-up window to save the file, click Save.
  4. Click on the installer. On the pop-up that appears, click Yes.
  5. The following pop-up window will appear. Click Next to proceed to the next step.

    Screenshot of Secure W2 installer popup window at start of installation process

  6. You will be redirected to a Single Sign-On page. Enter your active directory (AD) credentials and click Login.
  7. You will then receive a Duo prompt. Approve the prompt to proceed.
  8. The certificate will then install. Once it has finished, the pop-up window from step 5 will say “Joined…”. Once you see this screen, click Done.
  9. You will be redirected to the article "Configure VPN Client on your Computer, Tablet, or Phone". If you already have the Cisco Secure VPN Client installed, close out this tab.
  10. Open the VPN. In the window that appears, type in "vpn-exception.ucsd.edu", then click Connect.
  11. Enter your UCSD credentials and click OK.

Linux

  1. Navigate to the link provided to you in your approved exception request ticket.
  2. Ensure that the “Select your device” option at the bottom of the page says “Linux”. If not, click on the dropdown menu and choose Linux.

    Screenshot of the landing page for downloading the Secure W2 certificate on Linux devices with approved exceptions

  3. Click on Certificate Download. An installer will automatically download under the name “SecureW2_JoinNow.run”. If you get a pop-up window to save the file, click Save.
  4. Next, open the “Terminal” application on your device. Navigate to your Downloads folder and then run the command sh SecureW2_JoinNow.run
    1. When you have run this command, to go next, hit ENTER.

      Screenshot of terminal application running "SecureW2_JoinNow.run" and confirmation request to proceed with signing into a UCSD account

  5. You will be redirected to a Single Sign-On page. Enter your active directory (AD) credentials and click Login.
  6. You will then receive a Duo prompt. Approve the prompt to proceed.
  7. In the “Terminal” application, you will see messages that a certificate is being generated. Once you see “Joined…” the certificate has successfully installed on your device.
  8. Open the VPN. In the window that appears, type in "vpn-exception.ucsd.edu", then click Connect.
  9. Enter your UCSD credentials and click OK.

If you still have questions or need additional assistance, please contact the ITS Service Desk. You can call us at (858) 246-4357, email us at support@ucsd.edu, or submit a ticket at support.ucsd.edu.