Re: IAS-proxy and adding attributes part 2

From: Manjunath Bharadwaj [MSFT] (mbhara_at_online.microsoft.com)
Date: 03/21/05


Date: Mon, 21 Mar 2005 08:40:06 -0800

Mika,

  The custom dll has to export some functions. There is a list of functions
you need to export here:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ias/ias/internet_authentication_service_functions.asp

  You can write your dll in any language you choose, but I expect C/C++ to
be the easiest. I have not looked at the code (company policy) but there are
some sample dlls on sourceforge that can give you a starting point.

  There is a second method that is non extensible and unsupported by
Microsoft: you can modify the dnary.mdb to enable this attribute to be
modified and sent from your proxy to the backend RADIUS server. Look at the
thread a few weeks ago called "Locking down IAS and NAS". You should edit
the dnary.mdb and check the columb called "IsAllowedInProxyProfile" for
NAS-IP-Address. You should then see "Nas-IP-Address" in your proxy
attributes and you can modify that.

  Obviously this is not the preferred way to do it since you can end up
corrupting your IAS configuration.
  Hope it helps.
  Thanks, Manju

-- 
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
http://www.microsoft.com/technet/community/chats/default.mspx
Customer chat event:
Setting up Secure Infrastructure for Wireless Network (March 29, 2005, 
1:00 - 2:00 P.M. Pacific Time)
Setting up a secure infrastructure for wireless network can be complex and 
challenging. Bring your questions and comments to the table and interact 
with experts from the Internet Authentication Service team to get them 
answered. Find out how you can use IAS as the RADIUS server to set up an 
802.1x network and how you can set up underlying systems like Certification 
Authority service, Active Directory and Group Policy.
+++++++++++++++++++++++++++++++++++++++++++++++
This posting is provided "AS IS" with no warranties, and confers no rights


Relevant Pages

  • Re: IAS service start up problem
    ... And the IAS logs will be stored in %windir%\tracing. ... Setting up Secure Infrastructure for Wireless Network (March 29, 2005, ... with experts from the Internet Authentication Service team to get them ...
    (microsoft.public.internet.radius)
  • Re: IAS logging to SQL
    ... The IAS attribute information is stored only in the dnary.mdb file. ... Setting up Secure Infrastructure for Wireless Network (March 29, 2005, ... with experts from the Internet Authentication Service team to get them ...
    (microsoft.public.internet.radius)
  • Re: IAS logging to SQL
    ... "Locking down IAS and NAS") changes ias.mdb. ... to support costs and time. ... Setting up Secure Infrastructure for Wireless Network (March 29, 2005, ... with experts from the Internet Authentication Service team to get them ...
    (microsoft.public.internet.radius)
  • Re: IAS logging to SQL
    ... Authentication requests are processed normally BUT the value of ... > The IAS attribute information is stored only in the dnary.mdb file. ... > Setting up a secure infrastructure for wireless network can be complex and ... > with experts from the Internet Authentication Service team to get them ...
    (microsoft.public.internet.radius)
  • XPSP2 Wireless Network Startup with IAS and PEAP Auth.
    ... We have now successfully configured wireless network access over WPA, IAS ... The problem we have now is that despite we have a successfull computer ... authentication on IAS, ...
    (microsoft.public.internet.radius)