Multiple EAP-Types at WinXP clients

From: Eric J. (bt_hirosaito_at_gmx.de)
Date: 03/17/05


Date: 17 Mar 2005 03:39:48 -0800

hi,

we are using EAP-TLS and want to realise a fallback strategy if
something´s wrong with the client certificate.

Our idea is to set up a standard policy for the normal access with
dynamic vlan assignment for our intranet.
But if the PC is in the Active Directory and only has problems with
its certificate (expired for example) there should be a fallback
policy using PEAP which puts the PC into a special support-vlan.

Now my question:
At the IAS i can choose multiple authentication modes for the policy.
First using EAP-TLS and if that fails using PEAP.
How can i manage this on the client. That the client first tries to
authenticate via EAP-TLS and if that fails it tries to authenticate
via PEAP and gets access to the support-vlan where the certificate can
be renewed.
And if also PEAP authentication will fail we put the pc into a
guest-vlan or something.

Hope you understand what i mean. Its a bit tricky to explain it in
english :)

Greetz Eric



Relevant Pages

  • Re: The message must contain a wsa:To header
    ... My client app is not generating a trace file. ... the client is not applying the WSE policy at all because of an ... at ApplicationMessagingWS.Dispatch(String messageType, String ... look for a certificate with this subject name in the certificate store ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: security header is not present in the incoming message
    ... Similar problem appears when I run my client directly under IIS instead of under ASP.NET Development Server. ... There are no certificates in the certificate store that match the find value of 'CN=WSE2QuickStartServer'. ... 'Hello World with certificate policy. ...
    (microsoft.public.dotnet.security)
  • Re: How to secure specific web service from client side (WSE 2.0 SP1)
    ... I checked the policy tracing and found that the out-going message from ... I am sending the entire policy file of client side: ... describes which token type must be used for Signing.--> ... look for a certificate with this subject name in the certificate store ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • RE: Authorization issues with WSE 3.0 running on IIS 5.0
    ... The certificate is stored in your user profile, while the client application ... Change the policy to look in the "Local Computer / Personal" store for the ... > on IIS. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • RE: 802.1x, Computers, Wired Security
    ... Just to be clear....PEAP-MSCHAPvs and EAP-TLS both work for user auth. ... Please verify the certificates on the client machine that connect to 802.1x ... PEAP with EAP-TLS ... Is there a computer certificate that enrolled from the domain CA? ...
    (microsoft.public.windows.server.active_directory)