Re: Issues with IAS and Verisign Cert

From: James McIllece [MS] (jamesmci_at_online.microsoft.com)
Date: 09/09/04

  • Next message: James McIllece [MS]: "Re: Prblm: Radius, WLAN, roaming profiles and software install via group policies"
    Date: Thu, 09 Sep 2004 14:16:09 -0700
    
    

    "=?Utf-8?B?RA==?=" <D@discussions.microsoft.com> wrote in
    news:3E8226F0-C2CA-47B2-8F7A-C3F1B10F7042@microsoft.com:

    > I checked the authentication methods and everything is fine. But
    > here's were I get confused. The client authenticates and I verify
    > that through Event Viewer in the IAS server and the client is able to
    > surf the web for a few seconds and then it stops. I try 'ipconfig
    > /release' then 'ipconfig/renew' and I can't renew the ip. If I
    > disable and renable the wireless adapter the client can surf again and
    > then it goes back to the same issue. Any suggestions??
    >
    > "James McIllece [MS]" wrote:
    >
    >> "=?Utf-8?B?RA==?=" <D@discussions.microsoft.com> wrote in
    >> news:693B82F0-1C42-4461-B4F6-3D435F8D9E6A@microsoft.com:
    >>
    >> > Exporting and importing seems to work. The client can authenticate
    >> > but its very slow. I looked at the Event Viewer and I'm getting
    >> > this message.
    >> >
    >> > Fully-Qualified-User-Name = US\****
    >> > NAS-IP-Address = 131.*.*.*
    >> > NAS-Identifier = h
    >> > Called-Station-Identifier = 000d.bd01.109f
    >> > Calling-Station-Identifier = 000c.41fc.744c
    >> > Client-Friendly-Name = AP
    >> > Client-IP-Address = 131.*.*.*
    >> > NAS-Port-Type = Wireless - IEEE 802.11
    >> > NAS-Port = 423
    >> > Proxy-Policy-Name = Wireless Access
    >> > Authentication-Provider = Windows
    >> > Authentication-Server = <undetermined>
    >> > Policy-Name = Allow Wireless LAN Access
    >> > Authentication-Type = EAP
    >> > EAP-Type = <undetermined>
    >> > Reason-Code = 22
    >> > Reason = The client could not be authenticated because the
    >> > Extensible
    >> > Authentication Protocol (EAP) Type cannot be processed by the
    >> > server.
    >> >
    >> > By the way thanks very much for your help.
    >> >
    >> > D
    >> > "James McIllece [MS]" wrote:
    >> >
    >> >> >snip<
    >> >> >
    >> >> > I'm going to assume you are talking about the IAS certificate
    >> >> > store and not the client. If so yes the certificate is stored
    >> >> > in the IAS personal certificate store. I also checked the
    >> >> > client settings for guest access and the box is not checked and
    >> >> > PEAP is enabled.
    >> >> >>
    >> >> >
    >> >>
    >> >> Yes, I meant the IAS cert store, sorry I wasn't more specific. Did
    >> >> you try exporting and then importing the certificate? It would be
    >> >> hard to tell the difference if the certificate has access to the
    >> >> private keys or not from the UI. If you export and then import we
    >> >> can be certain.
    >> >>
    >> >> If that doesn't work, we'll need to see your tracelogs, so make
    >> >> sure tracing is enabled. To set tracing use the following command
    >> >> at the command prompt:
    >> >>
    >> >> netsh ras set tracing * enabled
    >> >>
    >> >>
    >> >> --
    >> >> James McIllece, Microsoft
    >> >>
    >> >> Please do not send email directly to this alias. This is my
    >> >> online account name for newsgroup participation only.
    >> >>
    >> >> This posting is provided "AS IS" with no warranties, and confers
    >> >> no rights.
    >> >>
    >> >
    >>
    >> You're welcome, I'm glad you have things working. As for the slowness
    >> of authentication...
    >>
    >> ....I ran this by some other guys on the team as I wasn't sure what
    >> the problem might be. One of them said:
    >>
    >> Sounds like they might not have enabled the right authentication
    >> method. Can they double check their settings on clients and make sure
    >> they’re using an authentication method that is enabled in the IAS
    >> matching policy.
    >>
    >> So you might want to check that out and let me know.
    >>
    >> --
    >> James McIllece, Microsoft
    >>
    >> Please do not send email directly to this alias. This is my online
    >> account name for newsgroup participation only.
    >>
    >> This posting is provided "AS IS" with no warranties, and confers no
    >> rights.
    >>
    >

    This sounds like an AP configuration issue. What AP are you using?

    -- 
    James McIllece, Microsoft
    Please do not send email directly to this alias.  This is my online 
    account name for newsgroup participation only.
    This posting is provided "AS IS" with no warranties, and confers no 
    rights.
    

  • Next message: James McIllece [MS]: "Re: Prblm: Radius, WLAN, roaming profiles and software install via group policies"

    Relevant Pages

    • Re: 802.1x Wired Auth and Authentication
      ... So I'm configured for EAP-TLS auth. ... I am getting errors on both the IAS server and Client. ... Wired 802.1X Authentication failed. ...
      (microsoft.public.internet.radius)
    • Re: IAS to authenticate CISCO VPN traffic
      ... > I just closed a TAC with CISCO about this issue and they are pointing to ... > IAS server as the problem... ... I created a client within IAS called ... > Within this profile Under authentication and encryption I have tried ...
      (microsoft.public.internet.radius)
    • IAS to authenticate CISCO VPN traffic
      ... I just closed a TAC with CISCO about this issue and they are pointing to the ... I have a cisco router configured with a group VPN key, and a IAS server ... CiscoRouter wuth the correct shared secret and I have set the Client Vendor ... Within this profile Under authentication and encryption I have tried ...
      (microsoft.public.internet.radius)
    • Re: Windows Authentication, Single sign on and Active Directory
      ... service proxy client fails to connect due to authentication failure and then ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... The server is always in the domain. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: BASIC authentication Issues with IE - Part II - Solved but WHY?
      ... it does not know the difference between a request from IE or from ... some other HTTP client. ... Some other authentication schemes are more ... IIS can sometimes remember the token for a particular set of credentials so ...
      (microsoft.public.inetserver.iis.security)