Re: AD required to use IAS?

From: LiquidNoize (mike.made_at_att.net)
Date: 08/24/04


Date: 24 Aug 2004 09:01:14 -0700

Thanks James. That's good news!

"James McIllece [MS]" <jamesmci@online.microsoft.com> wrote in message news:<Xns9544853912BCFjamesmcionlinemicros@207.46.248.16>...
> mike.made@att.net (LiquidNoize) wrote in
> news:d0d6d39d.0408131118.7619b443@posting.google.com:
>
> > I want to set up wireless users to authenticate via IAS to get access
> > to the network. Does the IAS server have to be in a domain or can I
> > just use local server accounts? Also, would I use peap-ms-chapv2 for
> > this? It will only be for 5 users so I would like to avoid AD right
> > now if possible. Thanks -Mike
> >
>
> No you don't need AD, you can just configure user accounts on the IAS
> server's security accounts manager (SAM) database.
>
> If you want to use PEAP-MS-CHAP v2 as the authentication method, you will
> need to purchase a server authentication certificate from Verisign (or
> another company) whose root CA certificate is already in the Trusted Root
> Certification Authorities store on client computers. (In other words, the
> IAS server must have a certificate that is issued by a CA that clients
> already trust -- otherwise you would have to deploy Certificate Services
> and then enroll certs to clients, which you don't want to do in your
> circumstance.)
>
> If you look at the IAS Help, you will see checklists that step you through
> how to set up secure wireless remote access policy with PEAP. Also see the
> Verisign whitepaper, "Obtaining and Installing a VeriSign WLAN Server
> Certificate for PEAP-MS-CHAP v2 Wireless Authentication" at
> http://www.microsoft.com/downloads/details.aspx?FamilyID=1971d43c-d2d9-
> 408d-bd97-139afc60996b&DisplayLang=en
>
> Another good one: "Enterprise Deployment of Secure 802.11 Networks Using
> Microsoft Windows" at
> http://www.microsoft.com/windowsserver2003/technologies/ias/default.mspx,
> although this whitepaper assumes you are using AD.



Relevant Pages

  • Re: IAS CRL problem
    ... one with CA and IAS installed the other ... If I revoke the certificate of the user and then try to authenticate ... Some how the CRL isn't correctly updated to the other IAS server. ...
    (microsoft.public.internet.radius)
  • Re: 802.1x Authentication
    ... MD5, although MD5 is available for VPN client. ... Your IAS server must have a certificate. ...
    (microsoft.public.internet.radius)
  • Re: PEAP 802.1x IAS - only works if previously logged in over wired connection.
    ... certificate services was deployed and IAS ... authenticate the IAS server via wireless. ... then successfully authenticate the IAS server cert when user authentication ...
    (microsoft.public.internet.radius)
  • Re: IAS CRL problem
    ... one with CA and IAS installed the other ... If I revoke the certificate of the user and then try to authenticate ... "After the old certificate is revoked, IAS will continue to use it until ... and the Transport Layer Security cache time expiry have been modified ...
    (microsoft.public.internet.radius)
  • Re: Logging to AD domain from wireless?
    ... you can do automatic certificate enrollement by group policy. ... Yes, you can configure a certificate authority, an IAS server (Microsoft ... configure your access point to authenticate users to this newly configured ...
    (microsoft.public.windows.server.networking)

Loading