WPA EAP-TLS

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Steve (no-address_at_hatespam.com)
Date: 06/20/04


Date: Sun, 20 Jun 2004 09:41:32 GMT

General questions on WPA and IAS authentication of a WPA EAP-TLS client with
the MS CryptAPI.

I am trying to understand what would be involved in supporting a
non-Microsoft WPA client where the client has embedded within it an X.509
certificate. The embedded certificate would NOT have user identifying
information in it, but would instead have information related to the device
(CN=serial number for example). In effect this is a 'computer certificate'
although this client would not be part of a domain and has nothing to do
with Microsoft's computer certificates.

I believe the first thing I would need is a CSP that is an RSA Schannel CSP.
Once I had my own CSP, how much control does my CSP have to verify the
client certificates? Does IAS and the CryptoAPI enforce any expectations on
the contents of a client certificate that is used for WPA if the certificate
is in fact mapped to a non-Microsoft CSP?

Steve



Relevant Pages

  • Re: 802.1x wireless lan how to?
    ... wireless client PC is getting the certificate from the server using auto ... certificate auto enrollment after a couple of days of battle. ... or WPA with TKIP otherwise. ...
    (microsoft.public.windows.server.sbs)
  • Re: Wireless WPA on SBS not authenticating
    ... Automatic certificate enrollment for local system failed to contact the ... Guess that means im not gettin anything so it must be my client or router. ... Everything needs to match exactly - for example, WPA and WPA2 are not ... you could try updating the NIC drivers on the wireless ...
    (microsoft.public.windows.server.sbs)
  • Authorizing a EAP-TLS client
    ... again to WPA EAP-TLS authentication using IAS. ... Given that a client has a certificate that contains specific information ...
    (microsoft.public.internet.radius)
  • Re: Wireless WPA on SBS not authenticating
    ... When the client PC boots, does it log any auto enrollment errors in its application log? ... I know you've verified the correct certificate is installed, but that Guest thing is weird - not something I've seen before. ... Everything needs to match exactly - for example, WPA and WPA2 are not ... Failing that, you could try updating the NIC drivers on the wireless client, ...
    (microsoft.public.windows.server.sbs)
  • Re: Checkpoint smart defance as IPS
    ... *any* SSL/TLS communication without tampering anything on the client ... website a client visits on-the-fly. ... don't have private key for the certificate on that website. ...
    (Security-Basics)