Re: does IAS fully support RFC 3579?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: James McIllece [MS] (jamesmci_at_online.microsoft.com)
Date: 08/26/04

  • Next message: Peter K: "Re: PEAP error message with CA and IAS"
    Date: Thu, 26 Aug 2004 15:44:35 -0700
    
    

    jeffc@att.com (Jeff Carlton) wrote in
    news:9a230cfc.0408121133.7bd5a3eb@posting.google.com:

    > Did Microsoft do anything different in implementing the EAP-TLS specs
    > for the IAS server? If so, what?
    >
    > In other words, if I implement the RFC 3579 (RADIUS support for EAP)
    > specs exactly, then we will be able to work with IAS. Is this a true
    > statement?
    >
    > Thanks.

    This RFC is fairly new and updates the previous RFC 2869 implemented in
    WS03 IAS, so RFC 3579 has some new features we don't currently support,
    such as the following:

    1. EAP Start
    2. Error-cause attribute in invalid packet handling
    3. Identifier Space
    4. Role reversal
    5. Returning user-name attribute in Access Accepts
     
    And there might be 1 or 2 other things, which I will post if I obtain that
    information.

    -- 
    James McIllece, Microsoft
    Please do not send email directly to this alias.  This is my online account 
    name for newsgroup participation only.
    This posting is provided "AS IS" with no warranties, and confers no rights.
    

  • Next message: Peter K: "Re: PEAP error message with CA and IAS"

    Relevant Pages

    • How to create a client for EAP-TLS
      ... I trying to build a client to interface with IAS using EAP-TLS. ... client will be used for smartcard authentications w/ digital ... Any suggested RFC documentation besides the following? ...
      (microsoft.public.internet.radius)
    • Re: IAS server stops authenticating workstations and users
      ... Have you tested communication between the IAS server and the RADIUS clients ... Also wondering if you have viewed the IAS ... The IAS server stopped logging. ... server and the authentication process has resumed. ...
      (microsoft.public.internet.radius)
    • Re: EAP-TLS Radius problem
      ... Do I understand you correctly that with IAS it is not possible to ... domain that the IAS server is in? ... server that is a member of Domain 1. ... Domain1 runs a Radius server to do authentication for wired 802.1x. ...
      (microsoft.public.internet.radius)
    • Re: Radius Server W2k 2003 without AD ??
      ... SAM user accounts database on the Windows Server 2003 IAS server. ...
      (microsoft.public.internet.radius)
    • Re: 3com wireless AP with IAS problem
      ... Have you configured your IAS server with a server certificate? ... If there is no server certificate you will not be able to do PEAP ... You can ask about RADIUS, IAS, 802.1x, Active directory configuration and Certificate services, related to IAS and RADIUS ...
      (microsoft.public.internet.radius)