Re: CA Role in 802.1x



=?Utf-8?B?QW5keQ==?= <Andy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:96A19608-2550-476A-871E-9281EF495C4B@xxxxxxxxxxxxx:

Hi James,
Let's say I have EAP-TLS setup correctly and I have only one CA on the
network. What will happen if CA goes down or is taken offline. Are
users able to authentication and login to the network?

Yes. The CA is not contacted by IAS while it authenticates and authorizes
connection requests.

IAS does make sure that it trusts the issuer of the certificate, though --
it does this by looking in the Trusted Root Certification Authorities
certificate store for the Local Computer. If there is a CA cert there from
the CA that issued the connecting user or client cert, IAS trusts the cert.
(It also checks other properties of the cert to verify that it is valid and
meets the minimum client certificate requirements).

IAS also periodically queries either the CA or AD (can't recall right now)
for the most recent certificate revocation list (CRL). Info on CRLs is in
Certificate Services Help on the box.



--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: Dummies Guide for RADIUS/Certs
    ... I have set up IAS. ... client computers impacts certificate enrollment. ... configure Group Policy for domain member wireless clients so ... Cert Templates that is now enrolled on the IAS server. ...
    (microsoft.public.internet.radius)
  • Re: iPaq 5555 WPA Authentication
    ... Auto-enrollement would leave the certs on the machine. ... auto-enrollment is used to give the network admin some slck when it comes to ... After that the cert should always be ... >> It sounds like you need to add a user certificate to access the ap, ...
    (microsoft.public.pocketpc.wireless)
  • Re: Mobile 2003 Radius authentication requirements
    ... > So where does the cert com from "using TLS"? ... I implemented 802.1x RADIUS> authentication on my domain and did not have a CA installed. ... So you are saying that IAS creates its own> Certificate ...
    (microsoft.public.internet.radius)
  • Re: PEAP auth with Verisign
    ... I'd also make sure that the client machine trusts the cert chain. ... You mentioned a root server cert that is generated by IAS. ... >I purchased a Verisign Class 3 WLAN server certificate ...
    (microsoft.public.internet.radius)
  • Re: IAS System Rights / IAS + Win2003 SP1
    ... Check that the certificate you have received from verisign meets the IAS ... 3/ Click "Edit profile" button ... The cert is registered correctly in the computers cert store ...
    (microsoft.public.internet.radius)