Sign in once. You're all set.
AllSet gets your devices onto UC Irvine Wi-Fi. You sign in one time, and your phone, laptop and tablet connect on their own from then on. No Wi-Fi password to remember, and none to type in wrong.
The networks it sets up
Two of these are the ones you will use every day. The third is for the things that have no way to log in.
UCI-WiFi
The campus network, and the one you want on your phone and laptop. AllSet gives your device a certificate instead of a password, so it connects by itself anywhere on campus. Nothing to type, nothing to mistype, and nothing to forget over summer.
eduroam
The same sign-in works at thousands of universities worldwide. Set it up here once and your laptop joins the Wi-Fi at Berkeley, Oxford or a conference centre in Tokyo without you doing anything at all.
The IoT Network
A games console, a smart TV, a printer or your own travel router has no screen to type a password into. These join by registering the device once, and AllSet walks you through it.
Open to personal devices today. Over time this network is intended for headless devices, the ones with no screen or keyboard, while everything that can sign in moves to UCI-WiFi.
Sign in with a password you already know
This is the part people worry about, so it is worth saying plainly. There are two ways to sign in to AllSet, and you only need to remember one of them. Pick whichever you actually use.
Your UCInetID
The one you use for most UCI systems. If you sign in to campus services regularly, this is probably the password in your muscle memory.
Microsoft 365
Your UCI email and Teams password. If you work at UCI Health this is the one you already use to sign in to Health systems, so it is probably the password you reach for without thinking. Plenty of students find the same thing. Either way, it works here.
The hard part was never the password
Think about how often you sign in to a web page. Your browser fills it in, or your password manager does, or you simply know it and type it without looking. Nobody finds that difficult.
Now picture typing that same password into a Wi-Fi settings screen on your phone.
A little box in a settings menu
- No autofill, and your password manager cannot reach it.
- Fields called Identity and Anonymous identity, with no explanation of what belongs in either.
- A certificate warning asking you to trust something you have no way to check.
- When it fails, it usually says only "authentication failed".
An ordinary sign-in page
- The same page, the same box, the same habits you use every day.
- Autofill and password managers work, because it is just a web page.
- If you get it wrong, it tells you, and there is a link to reset it.
- You do it once. Your device is issued its own credential and never asks you again.
That is the whole idea. The difficulty was never the password people were asked for. It was being asked for it in a place where none of their usual help exists. So AllSet moves that moment to where everyone is already fluent, and after it your device carries on by itself.
How it works
- Sign inWith your UCInetID or your Microsoft 365 account, whichever you know. That is the only time you type a password.
- Your device makes its own keyIt happens on your phone or laptop, not on our servers. The key never leaves your device and we never see it. Nobody at UCI can hand over a copy of it, because nobody has one.
- UCI vouches for itWe issue your device a certificate, which is a credential that proves who you are without a password. Your device keeps it and uses it every time it connects.
From then on it is automatic. You walk onto campus and you are online.
Why this is safer than a password
The old way asked you to guess a username format, pick between two passwords that are not the same, and then tap Trust on a warning with no way to tell a real UCI network from a fake one set up in a coffee shop.
AllSet removes all of that. The most important part is the last one: your device now checks the network before it says anything. A fake access point cannot collect a password you never typed.
For the technically curious
Your device generates an EC P-256 key pair in its own secure storage and sends us only a certificate signing request. On Apple devices the key is created inside the keychain during profile install and is never exportable.
We issue a client certificate from a dedicated UCI certificate authority whose signing keys live in AWS KMS and cannot be exported, only used to sign. Authentication is EAP-TLS, so no password is transmitted at any point.
Your device validates the RADIUS server's certificate and its name before completing the handshake, which is what makes an evil-twin access point useless against it.
Access is not governed by the certificate alone. Cisco ISE checks your UCI account at every reconnection, so when an account is disabled, access ends by itself. There is no revocation list to publish and no registry of devices to maintain.
What we keep, and what we don't
- Your certificate is issued to you and stored on your device.
- A log line recording that an enrollment happened, and when.
- We never receive your private key. It is made on your device and stays there.
- We never see your UCInetID password. Sign-in happens through UCI's own login.
- We keep no list of your devices, and no browsing history of any kind.
What being connected does, and does not, get you
Worth knowing before you go looking for something and think you have done it wrong. AllSet connects your device. That is the internet, campus websites, and everything open to the university generally.
A few things need more than a connection, and they are decided somewhere else entirely.
Sensitive applications
Systems like KFS and the timesheet system TRS want ZotDefend running on the computer you are using. It is UCI's security package: threat detection, anti-malware, vulnerability scanning, VPN, disk encryption and a posture check. What matters is that the software is there, not who owns the machine.
If OIT or your department manages your computer, you already have it. Faculty and staff who look after their own machines can install it themselves, free, through Jamf on a Mac or BigFix on Windows. Many do exactly that so they can work from home.
Restricted areas of the network
Some resources, a sensitive file share for example, sit on protected parts of the network. Reaching those depends on being in a security group your department manages, which is requested separately and has nothing to do with your device.
Who it's for
Everyone at UCI, with their own devices. It is designed so you can do it from home before you arrive, on the day you move in, or from a bench outside the library in October when you finally get round to it. All three work the same way.
Questions or something not working? oit@uci.edu