Chrome Version: Tested on 67 and 68
Network info: 802.1x PEAP network pushed via policy from CPanel
Steps To Reproduce:
(1) From CPanel configure a WiFi network using PEAP and set the username and password (either statically if using a service account or to ${LOGIN_ID} and ${PASSWORD} as per https://support.google.com/chrome/a/answer/2634553?hl=en#top&add&wifi&thirdparty&variables&change&managecerts&autoconnect&
(2) Connect to the configured network from a managed Chromebook
(3) Disconnect from the network
(4) Change the identity and password fields and press save
Expected Result: End user cannot modify network set via policy
Actual Result: End user can modify settings pushed via policy. Once changed there is no way to enforce the account details from the policy
Impact: devices are either disconnected from the network (if the end user enters invalid credentials) or are authenticated but to the wrong account (if the user enters valid credentials).
Comment 1 by rogerta@chromium.org
, Aug 27Owner: maxkirsch@chromium.org
Status: Assigned (was: Unconfirmed)