Re: PEAP auth with Verisign

From: Mark Gamache (mark.gamache_at_css-security.com)
Date: 02/02/05


Date: Tue, 1 Feb 2005 17:19:57 -0800

I'd verify that they Verisign cert is installed in the IAS server's machine
store. It may have auto imported into your personal store when you imported
it. I'd also make sure that the client machine trusts the cert chain.

You mentioned a root server cert that is generated by IAS. IAS can't
generate certs. Can you clarify this? Do you mean that you have a CA also
installed on the IAS server and it generated the cert? Or is the cert a
machine cert for the IAS server, but issued by a CA in your enterprise? If
I am reading between the lines correctly, I'd say that your client doesn't
trust the Verisign cert for some reason.

Cheers,

-- 
Mark Gamache
Certified Security Solutions
http://www.css-security.com
"symbol123" <seranky@sj.symbol.com> wrote in message 
news:030401c508c1$f868df60$a401280a@phx.gbl...
>I purchased a Verisign Class 3 WLAN server certificate
> and installed it on the MS Win2k3 RADIUS server. I then
> setup a Remote Access policy in IAS to do PEAP auth using
> this certificate.
> From my PPC device, I try to connect to the PEAP-enabled
> WLAN. The requests are reaching the IAS server but the
> authentication seems to be failing. Attached are messages
> from the Windows Event Log.
> Could not retrieve the Remote Access Server's certificate
> due to the  following error: The credentials supplied to
> the package were not recognized
>
> Access request for user RDEAP\test was discarded.
> Fully-Qualified-User-Name = <undetermined>
> NAS-IP-Address = 10.11.3.10
> NAS-Identifier = Symbol Access Point
> Called-Station-Identifier = 00a0f8b0aa65
> Calling-Station-Identifier = 00a0f8635eac
> Client-Friendly-Name = Symbol AP
> Client-IP-Address = 10.11.3.10
> NAS-Port-Type = Wireless - IEEE 802.11
> NAS-Port = 29
> Proxy-Policy-Name = <none>
> Authentication-Provider = <undetermined>
> Authentication-Server = <undetermined>
> Reason-Code = 1
> Reason = An internal error occurred. Check the system
> event log for additional information.
>
> The whole setup works if I use a server root certificate
> generated by IAS and copy it onto the PPC device and
> connect to the PEAP WLAN network.
>
> any thoughts on getting it work with a 3rd party CA cert ? 


Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync between Windows Mobile 5 and SBS2003 gives error
    ... If you don't find a cert here that matches the URL for OWA, you need to re-run the CEICW wizard on the SBS box and re-create the self signed cert. ... I exported the certificate straight from the server. ... Treo 700wx running Windows Mobile 5. ...
    (microsoft.public.windows.server.sbs)
  • Re: Dummies Guide for RADIUS/Certs
    ... I have set up IAS. ... client computers impacts certificate enrollment. ... configure Group Policy for domain member wireless clients so ... Cert Templates that is now enrolled on the IAS server. ...
    (microsoft.public.internet.radius)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)