Re: IAS CRL problem

Tech-Archive recommends: Fix windows errors by optimizing your registry



=?Utf-8?B?SmVyb2Vu?= <Jeroen@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:7D5AFE93-B52C-4597-AE2D-93F2E1115F0C@xxxxxxxxxxxxx:

Hi,

I've got 2 domain controllers, one with CA and IAS installed the other
only with IAS installed. When I try to authenticate a wireless client
with EAP-TLS both IAS servers accept the request.

If I revoke the certificate of the user and then try to authenticate
on the server with the CA installed I can't authenticate. On the other
server I can authenticate.

Some how the CRL isn't correctly updated to the other IAS server. I
set the CRL publication interval to 1 hour, but that doesn't matter.

Help would be appreciated.

Regards,

Jeroen



Hi Jeroen --

The product team has provided the following information for you:

"The CRL is most likely being cached by the second IAS server, and the
published CRL is not being checked because the cache is checked first. This
will be the case until the next expected update, which was provided by the
Next Update field the last time the CRL was checked. If the CRL publication
interval has been changed to one hour, this change will not reach the
second IAS server until its current copy expires. We do not support any
method to manually flush the CRL cache."

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: AD required to use IAS?
    ... >> I want to set up wireless users to authenticate via IAS to get access ... Does the IAS server have to be in a domain or can I ... > another company) whose root CA certificate is already in the Trusted Root ...
    (microsoft.public.internet.radius)
  • IAS Code 16
    ... >I have a Cisco VPN/Router trying to authenticate to our ... >AD domain using Windows 2003 IAS. ... >is allowed dial-up access using Windows authentication. ... The IAS server is registered in Active ...
    (microsoft.public.windows.server.active_directory)
  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... The do support WPA-EAP and the radius ... authenticate the computer and this is trying to authenticate the user and not ... If you can post perhaps 10 lines from the IAS log, ... represent my IAS server or the client laptops. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN 3005 to IAS authentication failure...
    ... Call it something like "VPN Users" or similar. ... install IAS using the Add/Remove Programs icon in Control Panel. ... we can now configure the PIX firewall as a RADIUS client. ... Any user that should be allowed to authenticate on a VPN connection will ...
    (comp.dcom.sys.cisco)
  • Re: IAS server and access points
    ... I use PEAP and passwords to authenticate wireless clients. ... I get an occassional message on my IAS server that says "A RADIUS ...
    (microsoft.public.internet.radius)